find_sensitive_access
Identifies principals with read or edit access to sensitive fields like SSN, DOB, account numbers, and credit cards, and shows the number of users with that access.
Instructions
Every principal granting read/edit on a field whose name matches a sensitivity pattern (SSN/DOB/account-number/card/comp/… from config), with how many users end up with that access (resolved through effective permissions, honoring muting). Recall is prioritized over precision — expect broad matches.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| snapshot_id | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||