Doppler
Connect Doppler to Iru Compliance Automation to collect project, environment, and secret-metadata evidence.
Iru connects to Doppler to confirm exactly who can access each environment's secrets, and track every change made to them. It reads the permission matrix and audit log directly, instead of relying on a team's memory of who has access.
Key Capabilities
- Verify project and environment access follows least privilege
- Confirm service tokens are scoped rather than universal
- Track secret access and changes as they're logged
Evidence Collected
- User permission matrix by project
- Service token inventory with scopes
- Audit log of secret access and changes