Access to sampled policy input content for Space admins.

Space admins that are not account admins can sample policy input and see sampled policy input titles and timestamps in the simulation dropdown, but can not see sampled policy input content. A lack of error messages or other feedback makes this confusing. According to support, only account admins can see sampled policy input.

My use case was about a push policy, but this may apply to other types of policies.

  • Enable Space admins to see sampled policy input that are sampled from stacks in the respective Space(s).

  • Add generic samples to policy simulation.

  • Add feedback about any lack of visibility that is due to access denied.

Additional background:

In a large organization context, Spaces can facilitate division of responsibility and enable keeping the number of account admins low and instead delegate administration through a hierarchy of Spaces. Unfortunately Spaces seem to have limited administrative functionality such as the example given above. Another example would be the inability for an administrative Stack to create new (sub-) Spaces unless it is a root Stack.

Workaround
Talk to support. Create your own sample data and use OPA/Rego Playground and/or OPA CLI.
Problem
Space admins that are not account admins can sample policy input and see sampled policy input titles and timestamps in the simulation dropdown, but can not see sampled policy input content.

Please authenticate to join the conversation.

Upvoters
Status

βœ… Completed

Board

πŸ’‘ Feature Requests

Tags

Policies

Date

8 months ago

Subscribe to post

Get notified by email when there are changes.