Skip to main content
Gathering Interest

Transformation capability access granularity

Related products:Authentication and Access Management
  • February 4, 2025
  • 0 replies
  • 102 views

Currently, tansformation:write defines access for running the transformation as well as deploying it.
Having two separate access levels (e.g. transfo:run and transfo:desploy, or simply keep transfo:write for deploying and have a new one transfo:run for executing the transfo) would greatly improve access control.

It would allow for better adherence to access policy without hurting user experience, since deploying transformations to an environment is much more delicate than simply running an already tested and stable transformation.

The same concept can be applied for functions!