Skip to content

Add access invitation policy auditor#464

Open
Davidrsdiaz wants to merge 1 commit into
SCIBASE-AI:mainfrom
Davidrsdiaz:codex/scibase-access-invite-11
Open

Add access invitation policy auditor#464
Davidrsdiaz wants to merge 1 commit into
SCIBASE-AI:mainfrom
Davidrsdiaz:codex/scibase-access-invite-11

Conversation

@Davidrsdiaz
Copy link
Copy Markdown

/claim #11

Summary

  • add a deterministic invitation and object-level access policy auditor for User & Project Management
  • detect expired active invitations, role escalation without owner approval, restricted dataset download bypasses, institutional-domain mismatches, unverified elevated roles, anonymous private access, audit-log gaps, missing download deny rules, and stale external collaborators
  • include synthetic JSON, Markdown, SVG, and short MP4 demo artifacts

Tests

  • node user-project-management/access-invitation-policy-auditor/test.js
  • node user-project-management/access-invitation-policy-auditor/demo.js
  • node user-project-management/access-invitation-policy-auditor/make-demo-video.js

All fixtures are synthetic and the module performs no account, identity-provider, private project, credential, SAML, ORCID, or external API access.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant