How to use Routing audit

Explains why a provider/model/perimeter was selected, which rules passed and which candidates were rejected.

What this section is for

Explains why a provider/model/perimeter was selected, which rules passed and which candidates were rejected.

Before you start

You need access to IAM.Router, the correct tenant/workspace and permission to read this data. Prepare a non-sensitive example value such as req_demo_20260806.

Buttons and forms

ControlWhat it does
SearchNarrows the visible list without changing server-side objects.
FiltersNarrows the visible list without changing server-side objects.
View decisionOpens the selected record and its available evidence or configuration.
ExportDownloads the current result set; active filters normally affect the export.

Primary path in the interface

  1. Open the application link above and sign in with the least-privileged role required for this section.
  2. Select the intended tenant or workspace. Do not continue while the header shows a different tenant.
  3. In the navigation, click Routing audit. The expected address is https://app.iamrouter.ru/routing-audit.
  4. Click Search. Enter the documented safe values: req_demo_20260806. Do not paste a production secret into a free-text field.
  5. Review every field before the final Save, Run, Publish or Confirm action. If a preview or validation control exists, run it first.
  6. Review the validation message or changed row. The result must match this purpose: Explains why a provider/model/perimeter was selected, which rules passed and which candidates were rejected.
  7. Only then continue to the next dependent section. Copy the request/correlation ID when the interface shows one.
  1. Open the deep link https://app.iamrouter.ru/routing-audit instead of navigating through the sidebar.
  2. Confirm the tenant/workspace after the page loads; a deep link must not silently switch scope.
  3. Before automating the API path, run this product-specific read-only or validation command. It proves reachability but does not bypass application permissions:
export IAM_ROUTER_URL=https://api.iamrouter.ru
export IAM_ROUTER_TOKEN='<token>'
curl --fail --silent --show-error "$IAM_ROUTER_URL/healthz"

How to verify the result

The decision contains tenant, policy version, selected route and reasons other candidates were excluded.

If it did not work

SymptomWhat to do
401 / sign-in screenSign in again, then return to this page. Do not put a session token in a URL.
403Check the selected tenant and request the documented role; retrying with the same role will not help.
404Verify the exact path and whether the feature is enabled in this environment.
409Search for an object named req_demo_20260806; continue with it or choose a unique name.
422 / validation errorCorrect only the highlighted fields. Keep identifiers lowercase unless the form explicitly allows otherwise.
429Wait for the displayed retry interval or reduce the request scope; do not start parallel retries.
5xx / timeoutRefresh once after the server has recovered; do not repeat a destructive action while its result is unknown. Save the correlation ID and timestamp for support.