Skip to Main Content
Status Delivered
Workspace * IBM Cloud Ideas
Created by Guest
Created on Jul 14, 2020

IBM Resource Access governance reports

I want to be able to answer a simple question when asked by an Auditor - Who has access to your COS Bucket?

Shockingly there is no way to generate an access report from a resource such as COS to see what service ID's and User ID's have access. If I have 100 users and 100 Service ID's I have to manually click each one and manually try to map user to Access group to access policy. It is unworkable. I do not know how any IBM customers are not screaming about this as it is about as basic requirement as you can get.

Idea priority Urgent
  • Guest
    Jul 17, 2020

    Hi Ben,

    Thank you for coming back on this. I was aware of the export option on the COS instance but that does not tell you (unless I am mistaken) who has access at the bucket level.

    As an example I have 1 COS instance with 20 buckets. Each bucket has different ACL's and permissions set.

    I have users who have direct access to the bucket. I have users and service ID'd that are members of an access group. There are different access policies and they are assigned to different buckets.

    IBM Cloud should have the ability to go to a bucket in COS and easily export or easily tell what users or serviceID's have access to that specific bucket.

    IBM solution is to go to each user and each service ID on a one by one basis and check the access. This is unworkable in an enterprise environment.

    Thanks

  • Guest
    Jul 15, 2020

    Hi Jamie,

    Please take a look at the resource access report capability. The resource access report allows a user to generate a point-in-time report of what identities (users, service ids, access groups) have access to a specific resource in an account. To access this report, you'll navigate to the resource list, select the resource of interest (in this case, a COS instance), and from the actions menu, select "export access report".

    Documentation for this feature is available here: https://cloud.ibm.com/docs/account?topic=account-access-report

    Please note, access to this report is governed by access policy. Therefore, only specific users can access this report. Please see required permissions in the documentation.

    Based on your feedback, I believe this feature meets your use case. Please let me know if we still have a gap after you have evaluated this.

    Thank you,

    Ben Lopez

    Offering Manager, Identity and Access Management

    PS:

    And a couple of screenshots to illustrate my instructions above:

    Resource list: https://cloud.ibm.com/resources

    Action menu:

    Export Access Report: