We need to periodically answer the question asked by auditors "who has change level access to the production environment?"
We know that we have the Resource Access Report (RAR) available but this is produced on a resource by resource basis. Running the Resource Access Report for all resources in our production environment is not practical.
For this reason we would like to be able produce the Resource Access Report for all resources within a specified Resource Group, essentially just run the RAR in a loop around all resources belonging to the specified resource group
Ideally we would like to be able to control the report further by setting runtime parameters such as
A choice to list all identities with access to resources or to list only identities with change level access
A choice to list all identity types with access to resources or to list only user identities or only service ids
Hope that makes sense
| Idea priority | High |
| Needed By | Quarter |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
We had a call today with IAM team and they requested that I update the ticket with some clarifications that emerged during our call
Our auditors would be interested in user type identities whether individual users with resource access or whether users granted resource access via an Access Group. They would not be interested in other identity types such as Service Ids
Auditors would be interested in any user that has a role that gives permission to carry out a change of some sort on a resource
Auditors would not be interested in the detail - a list by resource/ user or Access Group/user / role would work I think
The report be readable to a non technical person e.g. print user names, Access Group names, resource names as well as ids