Logging in Tomcat - Appian 18.4

We recently upgraded to 18.4. I am still in need of a security mechanism to ensure our production support team and administrators don't add users to groups from the Appian /design link. We would like to ensure only our Identity Management team has the ability to provision users to roles through an Appian application we built for them. I am looking for a way, perhaps by monitoring some type of Appian logs, to detect when/if an administrator adds a user to a group in secret so we can take the appropriate actions.

Has anyone encountered the same problem and are there solutions out there?

  Discussion posts and replies are publicly visible

Parents Reply
  • Yeah, that is a good idea. My coworker and I were talking about doing something similar. It would require having a daily process to store the group membership information on the database and keeping track of an audit for the group membership. Without an audit, we don't know if a change occurred or not. It is a lot of work but it is a solution. I am really surprised Appian doesn't write into their logs when a group membership change occurs through the /design. You would think that is top priority in terms of security...
Children
No Data