While historical security reporting (such as the Security Audit History Subject Area) provides invaluable hindsight into past changes, release managers and Security leads need real-time visibility into the active security state - both when reporting on current environments and before importing new security packages.
Problem Statement
Managing security configurations (Application Roles, IDCS/IAM Group, User-to-Group, and Group-to-App Role mappings) across FDI environments currently creates significant administrative overhead and operational risk:
- No Easy "Current State" Visibility: The Security Audit History Subject Area logs historical change events over time (Action Type and Action Date), but it lacks an explicit indicator for currently active mappings. Security teams are forced to maintain offline Excel spreadsheets to track target environment configurations and verify permissions.
- Audit vs. Preview Misalignment: Historical security reporting shows what changed in the past, but security teams cannot evaluate what is about to change right now prior to clicking "Import".
- Environment Sync & Drift Gaps: Detecting subtle security drift between Dev, Test, and Production requires manual cross-checking across menus or offline logs, increasing the risk of accidental privilege creep or broken row-level data access.
Proposed Solution: Dual Security Governance Enhancements
1. Active State Indicator ("Is Current Flag") in Security History Audit Subject Area
Enhance the existing Security Audit History Subject Area with a native Is Current Flag (Yes/No) attribute across all security mapping entities:
- Instant Current-State Reporting: Allows security teams to run a simple report filtering on
Is Current = 'Y' to extract the exact live Group-to-Application Role mappings and active user assignments in any environment. - Elimination of Offline Spreadsheets: Replaces legacy Excel trackers with a single, auto-refreshing source of truth directly inside the analytics layer.
2. Pre-Import "Security State Diff Engine"
Introduce a native Security Bundle Target Comparison Utility inside the FDI Console that executes a live delta check against the target environment's active schema before import:
- App Role & Source Group Mapping Delta Inspection: Highlights exact additions, updates, or deletions (if Replaces were an option) in Application Roles, and Group-to-Role associations.
- Visual Warning Banner: Flags potential access revocations or overwritten group mappings before changes commit.
- Pre-Deployment Compliance Export: Generates a downloadable change export for sign-off prior to deployment.
Business Value
- Ditch the Offline Spreadsheets: Maintains total current-state visibility directly within FDI reporting without manual Excel tracking.
- Unshakable Deployment Confidence: Security leads verify that only intended role and mapping updates hit Production.
- Effortless Drift Detection: Instantly compare live configurations across Dev, UAT, and Production to resolve environment drift proactively.