Skip to content

Recommendations

Recommendations are suggestions from Oblique to simplify entitlements without changing access.

Recommendations run automatically and regularly in your environment. When access changes are made that would affect a recommendation, it gets automatically updated.

Only admins can see recommendations. You can find recommendations for your tenant in the Recommendations tab under Manage. For resources with recommended changes, recommendations also appear above the entitlements table for that resource.

Create a request to apply the recommendation, or ignore a recommendation to dismiss it.

Recommendations are deterministic. They currently only suggest exact changes — that is, they don’t suggest changes that would alter the resulting access in any way.

Recommendations apply to entitlements on resources, and consider the role each entitlement grants. Two entitlements to the same resource only count as the same access when they grant the same role.

Recommendations cannot be disabled.

Oblique supports the following types of recommendations:

  • Redundant access, to deduplicate direct access where indirect access already exists. For example, if a user holds a role on a resource both directly and through a group or team they’re part of, the recommendation will suggest revoking the direct access. If the user’s direct entitlement grants other roles too, only the redundant role is removed.
  • Consolidate access, to migrate direct access for several users to group-based access, where a suitable group exists. For example, if three users who are all in Engineering hold the same role on a resource directly, the recommendation will suggest assigning that role to Engineering and revoking their direct entitlements, as long as no additional users would gain access.
You must be an admin to apply a recommendation.

From a selected recommendation in the Recommendations inbox:

  1. In the upper right of the recommendation, select Create request. This creates an open request.
  2. View the open request linked to the recommendation by selecting View request or clicking on the request name. The request will show that it was created from a recommendation underneath Requester on the request.
  3. Select Approve and apply to approve the request and apply the change.
You must be an admin to ignore a recommendation.

From a selected recommendation in the Recommendations inbox:

  1. In the upper right of the recommendation, select Ignore.

The recommendation will be dismissed and will not be shown again.