Can this be a derivedrole?
# help
j
Can this be a derivedrole?
c
No. Principal policies are for overriding rules for particular users.
What are you trying to achieve?
j
Just trying to understand Principal policies better.
I think I won't be writing Principal policies. I derive all my identities from JWTs and attr key/value pairs. So Principal policies don't make sense for my use cases.
I wouldn't want a specific User-X to have overriding rules.
c
Makes sense. Principal policies are mostly for exceptional cases like giving an auditor temporary access.
j
Exactly what I was thinking as well. A regulatory / oversight body is a good fit for this feature. Thank you.