> We have an internal API that just came out that lets a token view a
> resultant set of policy. However, we might be able to add the
> ability for this to be looked up via an accessor as well; that way
> anyone with appropriate access to view accessors for tokens could
> also understand the full set.
I'd certainly be excited to see this become an official feature!
This seems quite handy for debugging and verifying permissions caused
by interacting policies, and for writing new ones, particularly when
there's a sizable corpus of existing policies involved.
It'd be particularly nice for these use-case if the endpoint for the
resultant policy itemized which policy(/ies) contributed to each of
the final resultant rules.
Regards,
KT