bcgov / nr-forests-access-management

Authorization solution for BC natural resource sector
Apache License 2.0
8 stars 2 forks source link

Split FAM_ACCESS_ADMIN role by environment #378

Open gormless87 opened 1 year ago

gormless87 commented 1 year ago

As a Security-aware developer I want to segregate FAM access admin by environment So That the principle of least privilege is upheld*

Additional Context -FAM Administrators currently have access to grant admin access to all application in FAM (DEV, TEST & PROD), as per security requirements a change to this structure is required.

Acceptance Criteria

Definition of Done

**The Team needs an actual scenario AND a diagram to support this story!

ArogeG commented 1 year ago

Discussions with the team today points to the idea that this can be managed with the delegate access functionality.

basilv commented 1 year ago

Latest design has incorporated design for this - see https://apps.nrs.gov.bc.ca/int/confluence/display/FSAST1/Admin+Segregated+Schema+Design