Skip to main content

Policy Workbench & Simulation Panel: Granular View / Access Control

Enable granular, role-based access control for the Policy Workbench and Policy Simulation Panel, allowing non-account (non-root) administrators to:

  • View policy sampling results on a per-policy basis

  • Access sampled input data (where permitted)

  • Have read-only access to the Policy Simulation Panel

Doc referenced:

https://docs.spacelift.io/concepts/policy#is-policy-sampling-safe

Requested Enhancement

Introduce granular RBAC controls for policy-related tooling, such as:

  1. Per-Policy Sampling Access

    • Ability to grant sampling visibility on a per-policy basis.

    • Scoped access tied to specific policies, stacks, or spaces (if applicable).

  2. Read-Only Policy Simulation Access

    • Allow designated roles to:

      • View policy code

      • View simulation inputs and outputs

      • View sampling results

    • Without:

      • Editing policies

      • Modifying sampling settings

      • Gaining root-level privileges

  3. Role-Based Controls

    • New permission(s), e.g.:

      • policy:read_simulation

      • policy:read_sampling

    • Assignable to custom roles.

Status: ❌ Rejected2 comments

Log in to comment and vote

Comments2

  • Black Breeze

    •

    Feb 24

    Non-root users can use policy workbench for any policies and samples they have access to. As such, access control is working as intended, and does not limit the usability of the workbench.

    As discussed, Spacelift’s RBAC and custom roles only cover write operations, while this is effectively an idempotent read operation - so not a good candidate for extra scopes.

  • Black Breeze

    •

    Feb 24

    Thanks for taking the time to write it up, Skye! As discussed internally, the team is investigating overall access logic to the policy workbench, regardless of the new RBAC system.