rbac-audit Skill
Use when an operator or a scheduled task requests a periodic RBAC / least-privilege audit of the Zava Learning resource group — enumerate the real role assignments effective on the group, correlate each identity against actual Activity-Log usage to find standing access that is never used, flag over-privileged and direc Published by microsoft in sre-agent.
What is rbac-audit Skill?
Use when an operator or a scheduled task requests a periodic RBAC / least-privilege audit of the Zava Learning resource group — enumerate the real role assignments effective on the group, correlate each identity against actual Activity-Log usage to find standing access that is never used, flag over-privileged and direc Published by microsoft in sre-agent. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Security review
- Security review use cases
Technical details
- Install or run with Copy skill directory
When to use rbac-audit Skill
- Use it for security review.
Built with
Editorial notes
Source
- Creator: microsoft
- Repository: microsoft/sre-agent
- Skill file: labs/zava-learning/sre-config/agent-config/skills/rbac-audit/SKILL.md
What it does
Use when an operator or a scheduled task requests a periodic RBAC / least-privilege audit of the Zava Learning resource group — enumerate the real role assignments effective on the group, correlate each identity against actual Activity-Log usage to find standing access that is never used, flag over-privileged and direc
Skill instructions
Zava Learning — RBAC / Least-Privilege & Access-Usage Audit Resource Group: @@RG@@. Read-only audit — never create, modify, or remove a role assignment. This is a weekly governance review of who can do what here, and whether they actually use it. The goal is real least-privilege hygiene: surface over-privileged identities, direct (ungoverned) assignments, and standing access that has gone unused so a human can clean it up. Identity naming policy (governance reports name their subjects) The principals under audit (their display name / UPN / objectId and role) are the subject of this report — show them; an RBAC finding that hides the identity is useless. This is NOT the learner-PII the redaction standard protects. Still apply SearchMemory("zava-redaction") redact() to strip any secrets, tokens, credentials, or learner/customer PII that happen to appear, and never print secret values — but DO name the admins, service principals, and groups being audited. Where the names come from (do NOT
Explore related resources
Frequently asked questions
What is rbac-audit?
rbac-audit is a open-source AI agent skill with Copy skill directory. Use when an operator or a scheduled task requests a periodic RBAC / least-privilege audit of the Zava Learning resource group — enumerate the real role assignments effective on the group, correlate each.
Who is rbac-audit best for?
rbac-audit is best for reusing agent instructions, scripts, and references, security review workflows.
How do I install rbac-audit?
Install or run rbac-audit using Copy skill directory. Check rbac-audit for the latest setup command.
Is rbac-audit actively maintained?
rbac-audit may need a closer maintenance check before production use.
Auto-fetched from GitHub.