Due to the complexity of ABAC security rules and the high number of rules being created in the QMC, it is very easy to lose sight of what rules have been applied and who gets access to which kind of resources. Governance and overseeing of permissions in a self-service environment are paramount, which is the reason why an auditing feature was introduced in the QMC. From experience, it is convenient, and one of the most valuable resource-monitoring tools in the QMC. In general, it serves two purposes:
- Assistance in creating new security rules, by validating whether the applied expression logic has the expected outcome. This allows for a smooth trial and error when writing security rules, with absolute confidence at the end that it works as designed.
- For auditing permission of users. When new users get added to the system, you usually check whether they have...