Viewing a list of a subject's accesses
Note
This feature is in the Preview stage. To get access, contact tech support
Cloud Infrastructure Entitlement Management (CIEM) provides a centralized view of the full list of access permissions for the organization's resources available to individual subjects and groups.
Only organization members with the organization-manager.viewer
role or higher for the organization can view access permissions in the Security Deck
To get a list of a subject's accesses to the organization's resources:
-
Log in
as an organization user with theorganization-manager.viewer
role or higher for the organization. -
Go to Yandex Security Deck
. -
In the left-hand panel, select
CIEM. -
Click
Select subject and in the window that opens:-
Select the user, service account, user group, system group, or public group you need.
You may want to use the search feature.
-
Click Select.
-
This will open a list of accesses assigned to the selected subject. For each access, the list indicates the name/ID and type of resource, the role assigned to the subject for that resource, and information about whether the role was assigned to the subject directly or inherited from a group of which the subject is a member.
If the selected subject has multiple accesses, only some of them will be displayed. To display the remaining access permissions, сlick Load more at the bottom of the page.
Use filtering by resource ID, role ID, or access assignment method (Directly appointed
or Assigned via group
) as needed.
Cloud Infrastructure Entitlement Management does not display subjects' access permissions for Yandex DataLens billing accounts and resources.