Keep the lesson for the next incident
Document operation authority
Write the method, resource class, environment, required scope, expected denial, and owner beside the integration documentation. Distinguish authentication, authorization, and tenant selection. Avoid copying raw tokens or payloads into tickets, fixtures, or logs.
Keep redacted scope fixtures
Retain the allowed and denied synthetic requests, including one neighboring operation that must remain blocked. Store expected status, scope label, and policy revision with each fixture. Add the wrong-resource case if it helped separate access from identity.
Review unexpected access
Choose a signal for new denials, unexpected allowed operations, or repeated scope requests. Assign an owner and review date after credential or endpoint changes. Retire the follow-up only when the matrix still proves least privilege across the supported environments.
What to carry forward
Close learning with the operation matrix, redacted fixtures, permission owner, and recurrence trigger. Keep unknown policy behavior visible. The goal is a faster least-privilege comparison next time, not a promise that a credential will remain valid or correctly scoped forever.
Technical background: OpenAI documentation.
Keep the decision with the work.
Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.
Create an account See the product workflow