SSO Group Permissions pushed to data access in DCI
I got some customer feedback that has AWS IAM access groups baked into SSO that gives them access to data in CloudHealth based on those permissions. The customer would want to be able to use those permissions to tell DCI what access to billing data they should get. For example, if there is a Dev group that only has access to one project/account, use the IDP permissions to only give them access to billing data related to that account. When people come and go from the org this helps scaling access to data, while not having to manually create / remove Attributions.
-
Zach Almeida- Beers commented
I got some customer feedback that has AWS IAM access groups baked into SSO that gives them access to data in CloudHealth based on those permissions. The customer would want to be able to use those permissions to tell DCI what access to billing data they should get. For example, if there is a Dev group that only has access to one project/account, use the IDP permissions to only give them access to billing data related to that account. When people come and go from the org this helps scaling access to data, while not having to manually create / remove Attributions.