Policies

Identity & Secrets Intelligence continuously evaluates every secret, identity, and certificate in your Inventory against a set of built-in policies. Each policy is a named rule that checks for a specific risk pattern, an unrotated secret, an over-privileged identity, an expiring certificate and any match is surfaced as a finding with a severity, in Dashboard and Inventory. Policies is where you review that rule set..

What Are Policies

A policy translates raw inventory data into a "who can do what" risk signal: instead of just listing every secret, identity, and certificate you have, Policies tells you which of them violate a defined risk condition, and how severe that violation is. Findings roll up to Dashboard for an at-a-glance risk posture, and to Inventory for the underlying detail.

Policy Categories

Policies are organized into three categories, matching the object types Identity & Secrets Intelligence inventories.

Prerequisites

  • The account has the Identity and Secrets Intelligence feature enabled.
  • The user has admin-level Console access, or a role with the isi-access rule set to scoped or all.

For full RBAC setup instructions, see Control Access With RBAC.

Using Policies

To review policies:

  1. Log in to the Akeyless Console, and go to Identity & Secrets Intelligence.
  2. Select Policies.
  3. Review the available policies and their current status.
  4. Enable or adjust policies based on findings surfaced in Dashboard and Inventory.

Did this page help you?
Footer Section