<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do you bind “Segments” (saved filters) to IAM/RBAC policies? in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286043#M37570</link>
    <description>&lt;P&gt;We want Group A to use only Segments S1 and S2—and see only that data. They should not see or find any other Segments. Is this supported? If yes, how do we configure it (permissions/settings/API)? A short example would help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance for your help and any concrete examples—much appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Sep 2025 08:05:47 GMT</pubDate>
    <dc:creator>JonhBk201</dc:creator>
    <dc:date>2025-09-16T08:05:47Z</dc:date>
    <item>
      <title>How do you bind “Segments” (saved filters) to IAM/RBAC policies?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286043#M37570</link>
      <description>&lt;P&gt;We want Group A to use only Segments S1 and S2—and see only that data. They should not see or find any other Segments. Is this supported? If yes, how do we configure it (permissions/settings/API)? A short example would help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance for your help and any concrete examples—much appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 08:05:47 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286043#M37570</guid>
      <dc:creator>JonhBk201</dc:creator>
      <dc:date>2025-09-16T08:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: How do you bind “Segments” (saved filters) to IAM/RBAC policies?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286044#M37571</link>
      <description>&lt;P&gt;Segments cannot be used in IAM policies. You should use the dt security context in your permissions. You can use this to prevent people from accessing certain data in Grail.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 15:55:16 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286044#M37571</guid>
      <dc:creator>michiel_otten</dc:creator>
      <dc:date>2025-09-15T15:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: How do you bind “Segments” (saved filters) to IAM/RBAC policies?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286046#M37572</link>
      <description>&lt;P&gt;Thanks. One concern: we’re in a shared environment. If we enforce &lt;STRONG&gt;dt security context&lt;/STRONG&gt; for Grail, will that limit Davis’ correlation scope and risk hiding true root causes? Does Davis analyze all data and then filter by permissions, or is its analysis itself constrained by the security context? Any best-practice for shared envs?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 16:35:36 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286046#M37572</guid>
      <dc:creator>JonhBk201</dc:creator>
      <dc:date>2025-09-15T16:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do you bind “Segments” (saved filters) to IAM/RBAC policies?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286055#M37574</link>
      <description>&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;Setting up IAM policies gives or remove access to metrics, traces,&amp;nbsp; logs and entities for &lt;STRONG&gt;users&amp;nbsp;&lt;/STRONG&gt;in a group, not Davis itself.&amp;nbsp; So root cause analysis will work. Also problem correlation will work accordingly.&lt;/P&gt;&lt;P&gt;The only challenge you can face is that users are not allowed to view every event or entities that is referred to in the problem (dt security context prevents this of course).&lt;/P&gt;&lt;P&gt;I guess for a best practice I would recommend only reduce access if absolutely needed: f.e vendor 1 cannot see information of vendor B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tip: create a group that uses policy boundaries, that way you can use 1 permission to access data and bound the group to different boundaries.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.dynatrace.com/docs/manage/identity-access-management/permission-management/manage-user-permissions-policies/iam-policy-boundaries" target="_blank" rel="noopener"&gt;https://docs.dynatrace.com/docs/manage/identity-access-management/permission-management/manage-user-permissions-policies/iam-policy-boundaries&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR.&lt;/P&gt;&lt;P&gt;Michiel&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 09:36:07 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286055#M37574</guid>
      <dc:creator>michiel_otten</dc:creator>
      <dc:date>2025-12-10T09:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do you bind “Segments” (saved filters) to IAM/RBAC policies?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286059#M37575</link>
      <description>&lt;P&gt;Appreciate the thorough explanation, Michiel. Knowing Davis isn’t constrained by user IAM lets us proceed confidently. We’ll minimize restrictions (mainly to separate vendors/teams), adopt policy boundaries per group to reuse the same permission set, and set expectations that some events/entities in a problem may be hidden by dt security context. Thanks again for the guidance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Jonh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 18:08:42 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-do-you-bind-Segments-saved-filters-to-IAM-RBAC-policies/m-p/286059#M37575</guid>
      <dc:creator>JonhBk201</dc:creator>
      <dc:date>2025-09-15T18:08:42Z</dc:date>
    </item>
  </channel>
</rss>

