Policies
Identity & Secrets Intelligence continuously evaluates every secret, identity, and certificate in your Inventory against a set of built-in policies. Each policy is a named rule that checks for a specific risk pattern, an unrotated secret, an over-privileged identity, an expiring certificate and any match is surfaced as a finding with a severity, in Dashboard and Inventory. Policies is where you review that rule set..
What Are Policies
A policy translates raw inventory data into a "who can do what" risk signal: instead of just listing every secret, identity, and certificate you have, Policies tells you which of them violate a defined risk condition, and how severe that violation is. Findings roll up to Dashboard for an at-a-glance risk posture, and to Inventory for the underlying detail.
Policy Categories
Policies are organized into three categories, matching the object types Identity & Secrets Intelligence inventories.
- Secret Policies - Flag secret exposure risk and secret hygiene issues, such as unused, stale, or unrotated secrets. Learn more about Secret Policies.
- Identity Policies - Flag identity posture, privilege scope, and risky identity configurations. Learn more about Identity Policies.
- Certificate Policies - Flag certificate posture, lifecycle state, and certificate-related findings. Learn more about Certificate Policies.
Prerequisites
- The account has the Identity and Secrets Intelligence feature enabled.
- The user has admin-level Console access, or a role with the
isi-accessrule set toscopedorall.
For full RBAC setup instructions, see Control Access With RBAC.
Using Policies
To review policies:
- Log in to the Akeyless Console, and go to Identity & Secrets Intelligence.
- Select Policies.
- Review the available policies and their current status.
- Enable or adjust policies based on findings surfaced in Dashboard and Inventory.
Updated 36 minutes ago
