Step 1 — Find the denial in the audit log
Go to Audit Log and filter by event typeoauth.token_denied and outcome failure. Click the event to see the full details including the exact input that was evaluated.
Step 2 — Use the What-If Tester
Go to Policies → [your policy] → What-If and enter the same request:Step 3 — Fix the policy
Update the policy in the editor. Use Shadow Mode to test the fix in production before activating:- Update the policy with Shadow Mode on
- Monitor the audit log for 24 hours
- Click Activate when confident