DEV Community

Auth By Example
Auth By Example

Posted on

IdP login logs cannot answer "why was this allowed?"

It is 2 AM. Someone exported data they should not have. Okta shows Alice authenticated via SSO, MFA passed, session valid.

That proves she signed in. It does not prove why the application allowed invoice.export on that tenant.

Authentication logs and authorization evidence are different layers:

  • IdP events — who authenticated, MFA, group changes
  • Decision records — subject, action, resource, tenant, allow/deny, human-readable reason, policy version

A boolean { "allowed": false } proves a check ran. It does not explain the check. Scattered if user.role == "admin" checks scatter the evidence too — every service logs something different, or nothing.

Centralized policy gives every enforcement point the same evidence shape: grant → enforce → change → revoke. Agents make this worse (human → agent → tool → resource), so provenance has to cover the whole chain.

I work at Permit.io — we wrote up how to build that explainable authorization audit trail:

https://www.permit.io/blog/why-was-this-allowed-authorization-logs?utm_source=devto&utm_medium=social&utm_campaign=why-was-this-allowed-authorization-logs&utm_content=authbyexample-article

Top comments (0)