Discussion about this post

User's avatar
Neural Foundry's avatar

This definitely shifts how we thinkabout authorization governance. The distinction between audit (what a system does) and governance (whether what it does is legitimate) captures something that gets muddled in discussions. In my experience, teams build architectures but skip documenting intent in ADRs, then struggle explaining why access patterns exsit. Using AI to compare effective access against recorded intent is dunno, way more practical than retrospective discovery.

No posts

Ready for more?