OCI

Policy Analysis

Basic Filter • Advanced Filter • Inspector • Prospective Editor

Context Help

How To Use This Page

Run filters to load statements, click rows to open the standard fly-in inspector, and use Manage Prospective Statements to open the wide editor fly-in.

Principal subject matcher; supports | for OR.
Restrict by action type or include both.
IAM verb matcher; supports | for OR.
Inactive
Resource or family matcher.
Inactive
Matches normalized permission text.
Location clause matcher. "tenancy" or name of compartment.
Path where the policy is defined.
Raw statement text contains match.
Policy name contains match.
Final effective evaluation path.
Condition clause contains match.
Filter by parser validity state.
Advanced: filter helper actions

Resource → Family + all-resources

Builds resource|family|all-resources in Resource filter.

Family → members + all-resources

Builds family|resource1|resource2|...|all-resources in Resource filter.

Permission Lookup

Add individual PERMISSION elements to the Permission filter using the lookup fly-in. Searching for permissions clears the Resource filter because they are mutually exclusive and cannot exist together in the same policy statement.
Advanced: raw JSON payload override
No results yet
Tip: click a row to view more details.
Compartment / Policy Effective Path Statement Conditions Verb + Resource / Permission