DEV Community

Auth By Example
Auth By Example

Posted on

IdP login logs are not enough for SOC 2-style access reviews

Login and MFA events answer "who authenticated?" They usually do not answer "why was this action allowed or denied on that resource?"

For SOC 2-style access reviews, that gap matters. Reviewers want evidence that application controls actually enforced policy — not only that SSO worked.

Useful authorization evidence connects:

  • Identity — who (or which agent) made the request
  • Policy — which rule/version decided
  • Resource — which tenant/object/action was targeted
  • Result — allow and deny, with a reason

Explainable deny is as important as explainable allow. A deny shows the boundary held; an allow shows legitimate access had a clear reason.

We wrote up the evidence shape here (I'm with Permit.io):

https://www.permit.io/blog/soc2-explainable-deny?utm_source=devto&utm_medium=social&utm_campaign=soc2-explainable-deny&utm_content=authbyexample

Top comments (0)