Playbooks
Introduction
Playbooks can do the following
Playbooks can be used by 3 kinds of personas
Playbooks can be run in either of these ways
Playbooks can be executed outside of the tenant application
The following articles can walk through configuring and executing playbooks on BalkanID
Example Playbook usecases
Joiner
Leaver
Mover
Automatic daily just in time access grant at beginning of day and access revoke at end of day based on prior usage patterns
Automatic access reviews followed by approval or denial as well as remediation based on insights, scheduled on a cadence
Terminated (Action on Terminated users with active identities in AWS)
SoD (Github Non-Engineering Admins)
Suspend all identities with last login activity more than 180 days
Escalate SoD AND Privileged finding with actions
Quarterly, automatically create a “DRAFT” campaign for privileged identities in the organization
Notify employees who have not enabled MFA for certain apps
Auto-suspend/lock if an account does not have MFA enabled and found in a breach
If a finding is an SOD violation with unused access
Last updated
Was this helpful?

