Operations
Safe rollout process for role inheritance, resource policies, and tag policies.
Rollout Steps
- Seed system roles and validate baseline role assignments.
- Introduce custom roles and inheritance in low-risk projects.
- Apply resource policies and tag policies incrementally.
- Validate effective permissions with canary users.
- Monitor 403 spikes and permission-cache miss rate.
Rollback
- Remove newly added policies first.
- Revert role parent links if inheritance causes over/under-permission.
- Restore previous role assignments from audit records.
Was this page helpful?