Debug access
Oblique provides several ways to help you understand and debug access. These are shown on a user’s profile, or on a group’s or resource’s detail page. This includes:
- The entitlements list in the Access table shows you the access a user, group, or resource has.
- The access graph shows you the relationships between users, accounts, groups, resources, and roles. Select View graph to open it.
- The access change timeline under Access changes shows you recent events that changed access for the user, group, or resource.
When debugging why a user does or doesn’t have access, consider these common questions:
- Who has access to this resource?
- How does this user have access to this resource?
- How has access changed for this user or this resource over time?
- How is this user’s access different from others?
See what access a user or group has
Section titled “See what access a user or group has”To see what access a user or group has, navigate to the user’s or group’s detail page.
Under Access, you can see the resources the user or group has access to, grouped by integration, including roles, expiry, and how that access is obtained (directly or indirectly). Indirect access is when a user has access through a group they belong to.
You can search this table for resources which the user or group has access to.
See who can access a resource and how
Section titled “See who can access a resource and how”To see who can access a resource, navigate to the resource’s detail page.
For a resource, under Access, you can see the users, groups, and other resources that have access to the resource, and what roles they have. This includes the number of users and groups that have direct access and the total number of subjects having access.
See how a user or account has access to a resource
Section titled “See how a user or account has access to a resource”To see how a user has access to a resource, navigate to the user’s profile, and then next to Access, select View graph. This will show the access graph for the user, which shows the relationships between the user and the resources roles they have access to, including roles.
You can also open this view from the Access table on a resource’s detail page for a user. Identify the desired user in the table and then select More and then View graph.
You can see what your own accounts have access to, or admins can see that for all accounts. Select the account from the user’s profile page, or if it’s not tied to a user, from the integration’s Accounts tab.
See how access to a resource is obtained
Section titled “See how access to a resource is obtained”To understand how access to a resource is obtained, navigate to the resource’s detail page. Next to Access, select View graph. This shows the access graph for the resource, which displays the relationships between the resource and the users, groups, and other resources that have access to it.
You can also open this view from the Access table on a user’s, group’s, or resource’s detail page. Identify the desired resource in the table and then select More and then View graph.
See how access has changed over time for a user or a group
Section titled “See how access has changed over time for a user or a group”To see how access has changed over time for a user or a group, navigate to the user’s profile or the group’s detail page.
Under Access changes, you can see a timeline of access changes that affect this user or group. Alongside access being granted and revoked, the timeline records when the roles a subject holds on a resource change, such as a group member being promoted to its owner.
See how access to a resource has changed
Section titled “See how access to a resource has changed”To see how access to a resource has changed over time, navigate to the resource’s detail page.
Under Access changes, you can see a timeline of access changes that affect this resource.
Compare two users’ group membership
Section titled “Compare two users’ group membership”To compare two users’ group membership, navigate to the Groups page.
- Select Filter, then select the Members filter.
- Select the first user. The groups list is now filtered to groups that the first user is a member of.
- Again, select Filter, then select the Members filter.
- Select the second user. Change the filter from one of to none of.
The resulting filtered groups list will show groups that the first user is a member of, but not the second user.