In the DSH ecosystem, validating the integrity of Microsoft Entra access reviews often relies on the state of the platform UI, which is hard to trace in automated processes. The following introduces dsh-access-review-proof, an offline deterministic evidence plugin that answers a specific question: Does the provided access review activity cover each claimed entitlement, satisfy its risk-based review stages, and close each retain/revoke decision into a new post-review inventory?
Plugin Positioning and Background¶
This plugin is maintained by dongsheng123132 and licensed under MIT. It addresses compliance and consistency validation of review evidence. Microsoft Entra Access Reviews manage groups, applications, access packages, and roles. This plugin only validates the structured evidence provided; it is not an identity governance platform itself.
Core Functions¶
The plugin ensures the integrity and security of the evidence chain through a series of checkpoints:
- Timeline Integrity: checks the temporal records of review start, completion, deadline, closure, snapshot, and evaluation.
- Entitlement Coverage: ensures the declared entitlement set is covered exactly, with no omissions.
- Risk and Decisions: validates that risk-based stage counts are correct and that decisions remain continuous and ordered.
- Reviewer Independence: ensures independent reviewers for configured high-risk classes, excluding self-review situations.
- Binding Consistency: checks common review bindings across decisions, closures, and snapshots.
- Closure Logic: ensures that after review completion, each entitlement has only one closure action.
- Decision Matching: validates whether final retain/revoke decisions match active/revoked closure states.
- Receipt Validity: ensures revoke actions have a non-zero application receipt.
- Snapshot Partitioning: precisely partitions active and revoked states in the post-review snapshot.
- Security and Diversity: includes observer diversity checks and evidence freshness validation, as well as secret/raw rejection, workspace isolation, symlink defense, and content-based readback capability.
Installation and Enablement¶
Installing this plugin requires using DSH plugin management commands. Replace the path with the actual local path or a specific Git Commit Hash.
dsh plugin --profile <profile> add /absolute/path/to/dsh-access-review-proof
dsh plugin --profile <profile> add github:dongsheng123132/dsh-access-review-proof#<commit>
Typical Usage¶
After installation, it can be operated through Node.js scripts or DSH tools. The following are reproducible examples based on the README:
npm test
npm run check
node bin/dsh-access-review-proof.mjs inspect examples/closed.json
node bin/dsh-access-review-proof.mjs verify examples/closed.json
In the DSH runtime environment, available tools include dsh_access_review_inspect and dsh_access_review_verify. In MCP (Model Context Protocol) mode, the corresponding tools are access_review_inspect and access_review_verify.
Applicable Scenarios and Notes¶
- Applicable Scenarios: Use this plugin when you need to offline audit externally provided access review closure evidence (such as JSON files) and ensure that the evidence chain meets specific compliance requirements (such as observer diversity and risk-based stages).
- Permissions and Security: The plugin runs with the permissions of the current DSH process. Be sure to inspect the source code and license (MIT) before installation.
- Evidence Specification: Refer to
examples/closed.json. The manifest should contain only public IDs, timestamps, counts, and SHA-256 bindings. Credentials, account names, tokens, raw identity exports, or business text must not be placed in the manifest.
Summary¶
dsh-access-review-proof provides a rigorous offline validation mechanism for access review processes. It does not replace platform operations; instead, it serves as an evidence validation tool that ensures the review process conforms to predefined logical and security rules at the data level.