RBAC
Role‑based access control (RBAC) ensures that only authorized users can change policies or view sensitive findings.
Typical Roles
Many organizations define roles such as:
- Policy authors – create and modify policies and policy packs; limited to specific domains where possible.
- Compliance and security owners – approve new controls, review exceptions, and oversee posture.
- Operators – run evaluations, manage schedules, and coordinate remediation.
- View‑only consumers – application owners, auditors, and stakeholders who view dashboards and reports but cannot change policies.
These roles can be implemented using Cloudaware permission sets and profiles.
Principles
When configuring RBAC:
- Apply the principle of least privilege—only grant policy modification rights to users who need them.
- Separate policy design from policy enforcement where appropriate.
- Ensure auditors have read‑only access to findings, exceptions, and evidence.
Well‑designed RBAC reduces the risk of unintended policy changes and improves auditability.