Skip to Main Content
IBM - Cloud, PowerVS and Ceph aaS - Structured Ideas

This portal is to open public enhancement requests. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.

Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

Status Future consideration
Workspace * IBM Cloud Ideas
Categories Administration
Created by Guest
Created on May 30, 2025

Resource Access Report at Resource Group Level

We need to periodically answer the question asked by auditors "who has change level access to the production environment?"

We know that we have the Resource Access Report (RAR) available but this is produced on a resource by resource basis. Running the Resource Access Report for all resources in our production environment is not practical.

For this reason we would like to be able produce the Resource Access Report for all resources within a specified Resource Group, essentially just run the RAR in a loop around all resources belonging to the specified resource group

Ideally we would like to be able to control the report further by setting runtime parameters such as

  • A choice to list all identities with access to resources or to list only identities with change level access

  • A choice to list all identity types with access to resources or to list only user identities or only service ids

Hope that makes sense



Idea priority High
Needed By Quarter
  • Guest
    Sep 16, 2025

    We had a call today with IAM team and they requested that I update the ticket with some clarifications that emerged during our call

    • Our auditors would be interested in user type identities whether individual users with resource access or whether users granted resource access via an Access Group. They would not be interested in other identity types such as Service Ids

    • Auditors would be interested in any user that has a role that gives permission to carry out a change of some sort on a resource

    • Auditors would not be interested in the detail - a list by resource/ user or Access Group/user / role would work I think

    • The report be readable to a non technical person e.g. print user names, Access Group names, resource names as well as ids