Dot-Walk Scoping Security Enhancement: Feedback on Customer Adoption Experience
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 hours ago
Hello Community,
We've been evaluating the Dot-Walk Scoping Security Enhancement introduced with the Australia release and wanted to share some feedback on the customer experience, as well as hear how others approached it.
The security objective makes sense. Understanding and controlling cross-scope access is an important capability. However, the implementation and adoption experience felt more challenging than it needed to be.
Some observations:
- Customers are asked to enable logging, generate activity, analyze findings, identify required CSP/RCA records, assess impacts, and eventually determine whether enforcement is appropriate.
- The overall process can feel difficult to operationalize, particularly in mature instances with numerous integrations, applications, and customizations.
- The tooling identifies activity, but translating that activity into clear remediation actions often requires significant investigation and platform knowledge.
- It can be difficult to distinguish:
- expected platform behavior,
- customization-related access patterns,
- findings that require action, and
- findings that are informational only.
- Governance and readiness questions frequently become as important as the technical implementation itself.
From a customer perspective, it would have been helpful to have:
- A readiness dashboard showing the applications and access patterns most likely to be affected.
- Clearer prioritization of findings by risk and expected impact.
- More prescriptive guidance for determining when CSP records, RCA records, or alternative approaches are appropriate.
- Better visibility into known platform-generated patterns versus customer-generated patterns.
- A documented maturity model or go/no-go framework for enabling enforcement.
For organizations that have already completed this journey:
- What was the most challenging part of the assessment process?
- What guidance or tooling would have made the experience easier?
- Did you ultimately enable enforcement, and what criteria were used to determine readiness?
Interested in hearing how other customers approached the assessment and governance aspects of this enhancement.
Thank you.
