The problems we solve
-
Every permission modeled in the identity provider, which has become impossible to maintain.
-
Nobody can tell who had which right, or since when.
-
Reference data changed without a usable history.
-
An audit coming up with no evidence ready.
What we put in place
-
An identity provider (Keycloak or equivalent) for authentication and access to the applications.
-
Business permissions owned by each service, with a published catalog.
-
A log of access right changes and sensitive actions.
-
Usage snapshots, to trace what was actually used.