[HN Gopher] Show HN: Sym, define just-in-time access workflows i...
       ___________________________________________________________________
        
       Show HN: Sym, define just-in-time access workflows in code
        
       Hello HN,  My cofounder (jon918) and I started Sym three years ago
       because we were frustrated with how hard it was to manage access to
       cloud infrastructure. We wanted to build a tool for JIT access that
       was _actually_ designed for developers. We were wary of tools that
       tried to accommodate both devs and IT but ended up with usability
       compromises for both.  First, we figured no one wants another web
       app to log into so we let administrators define access workflows in
       Terraform and let developers request and gain access via Slack.
       That seemed to pay off: being code-based was a big plus for our
       early customers since it let them manage the logic in version
       control and test in CI/CD.  Second, we knew that updating
       permissions/roles/access was a major source of toil and risk in the
       world of cloud infrastructure. Have you ever tried to avoid
       annoying, persistent access requests by setting policies that are a
       bit more permissive than you'd like? We felt that fully automated
       just-in-time access + approvals could really help here. But we also
       knew that a simple approval tool could end up leading to request
       fatigue - kind of defeating the purpose. So we built an SDK to let
       you define checks in code (e.g. pagerduty.on_call,
       okta.is_user_in_group, github.get_repo_collaborators) in order to
       dynamically route requests or fast-track access when appropriate.
       This seems to be paying off: users are creating Slack-based
       approvals in front of different types of risky actions like
       production access, sensitive queries and triggering Lambdas.  We'd
       love your feedback on our approach so far. Does this make sense to
       you? Is this a tool you'd use? What would you want to see out of
       it?  To learn more, check out the video that Nick (nmeans (Sym
       VPEng)) made [1]. You can also check out our docs [2] or set up
       your own flow [3].  thanks!  -adam  [1]
       https://vimeo.com/815222490/c717c18c42  [2] https://docs.symops.com
       [3] https://symops.com/signup
        
       Author : abuggia
       Score  : 42 points
       Date   : 2023-04-06 14:45 UTC (8 hours ago)
        
 (HTM) web link (symops.com)
 (TXT) w3m dump (symops.com)
        
       | eropple wrote:
       | Oh cool, glad to see this hit HN. I know Adam and Jon from way
       | back and they're good folks. Congrats on how far you've come with
       | this!
        
         | abuggia wrote:
         | Thanks Ed!
        
       | zwitkali wrote:
       | Love the code-first approach to building a JIT access management
       | tool. Would love to see y'all build a pulumi provider to double
       | down on the code-first approach.
        
         | abuggia wrote:
         | Providing support for other infra-as-code solutions like Pulumi
         | is definitely on the roadmap!
        
       | skuenzli wrote:
       | I love this approach to integrating access control workflow into
       | existing workflows using code.
       | 
       | Really feels like security can actually be "everyone's job" when
       | you're able to make good access management decisions from within
       | your existing tools and their supporting context.
        
         | jon918 wrote:
         | Thanks - we've definitely seen Sym help our early customers
         | safely distribute access decisions. Because the flows are
         | managed in code, teams also get visibility into how these rules
         | are defined and can contribute to improving them, as well as
         | extend to new use cases.
        
       | jon918 wrote:
       | Hey I'm Adam's co-founder, we'd love feedback from the HN
       | community on what we've been working on!
        
       ___________________________________________________________________
       (page generated 2023-04-06 23:01 UTC)