Hi Vaun, It is an interesting question. I will start with the caveat that this is functionality which is not yet supported by ABAC. We haven't yet implemented the ability to use ABAC to deny access to Genesys Cloud. This is a use case we will be adding shortly. So, some of the behavior around this has yet to be defined. From your perspective, what would that desired behavior be?
Ultimately, as long as we have a way to identify the user or group of users defined in the policy, we can deny access at any time. So, for example, a user who is already logged in prior to 5pm might continue to be logged in (their access tokens aren't automatically invalidated) but the ABAC policy could prevent them from accessing resources post 5pm. That might not be a desirable outcome so the policy could be implemented in a different manner such that, once the user has access, they continue to have access until they logout or their tokens expire. Similar to getting access to a conference call which is locked at a certain time. Once you are in, you are in, but if you don't get in ahead of the deadline, you are blocked. So, in summary, yet to be defined but definitely something to think about.
------------------------------
David Murray
Principal Product Manager
Genesys Cloud
------------------------------
Original Message:
Sent: 11-08-2024 23:55
From: Vaun McCarthy
Subject: UI Change: Attribute Based Access Control (ABAC)
Hi David, I'm curious. Where you mention here environment access and time of day, what would a user experience if we were to do something like say "this group of users can only access the environment 9am-5pm". What would happen to that user at 5:01pm?
------------------------------
Vaun McCarthy
------------------------------