After you create an Access Control Policy, Cryptographic Security Platform Vault tracks the changes made to the policy details, rules, and permission lists. You can access the change history in for any policy in the Cryptographic Security Platform Vault webGUI.

  1. Log into the Cryptographic Security Platform Vault for VM Encryption webGUI on any node in the cluster using an account with Cloud Admin privileges in the Cloud Administration group under which you want to add the policy.
  2. In the top menu bar, click Workloads.
  3. Navigate to the Access Control Policies tab.
  4. Select the policy whose change history you want to view in the list.
  5. In the Policy Details area below the table, look at the Version field. If changes have been made since the policy was created, the Cryptographic Security Platform Vault webGUI displays the View Change List link. Click this link to view the Change Version History dialog box.

    Note: If the version number is higher than 1 but there is no View Change List link, that means the changes were made while the policy was being created. Cryptographic Security Platform Vault does not begin logging the changes until after the policy has been saved for the first time.

  6. To view the details of a particular change, click any of the fields for that change. The Cryptographic Security Platform Vault webGUI displays the old version and the new version side by side.

    For Windows rules, the Changes in Version dialog box also contains a Rule Type field that identifies which kind of rule was changed. The Rule Type can be:

    • 1—Filesystem-Level Access Rule
    • 2—Block-Level Access Rule
    • 3—Filesystem-Level and Block-Level Access Rule
    • 4—Folder-Level Access Rule

    Note: In order to keep the changes easy to identify, Cryptographic Security Platform Vault creates a new version each time you click Save during the process. For example, if you add a permission for the user fred and click Save, that becomes a new version. If you then edit the permissions list again and add martha, that becomes a different version. If, however, you edit the permissions list and add fred, then you click Add Another and add martha then you click Save, the addition of fred and martha are both part of the same version.