Access Reviews (internal)
Access to systems/services is audited regularely. When audit is done, there's a helper script to create tasks and list of users with access. Script can be found in here:
https://github.com/Attracs/attracs-linux-playbooks/gcp/audit/run_access_all.sh
One can run audit individually. These doesn't cover all the cases and relies user, who is running the audit scripts, to have enough access to these services.
Configuration of the auditors and services can be found in here: https://github.com/Attracs/attracs-linux-playbooks/gcp/audit/config/config.yml
Tokens for services are in here: https://github.com/Attracs/attracs-linux-playbooks/gcp/audit/config/config_enc.yml These tokens need to updated to match user who has access to environments. In this case those tokens are from DevOps Manager