heroui logo

Asana Workspace Guest Invite Permissions Anyone

Panther Rules

View Source
Summary
This rule is designed to detect changes to guest invitation permissions in Asana workspaces. Typically, only a limited number of users (super admins) are allowed to invite guests to workspaces. When the settings are changed to allow anyone to invite guests, it raises security concerns as it could potentially allow unauthorized users access to sensitive workspace data. The rule monitors for the event where the guest invite permission is altered from 'admins_only' to 'anyone'. It logs such changes, recording details such as the actor responsible, the IP address from which the change was made, the user agent, and the original and new permission settings. This assists in maintaining a secure environment by ensuring that any unauthorized changes can be quickly identified and addressed.
Categories
  • Web
  • Application
  • Identity Management
Data Sources
  • User Account
  • Application Log
Created: 2023-02-01