Build a useful investigation brief
Build permission fixtures
Create one allowed read, one denied write, one wrong-tenant resource, and one similar identity with insufficient role. Record expected result and authority before execution. Use synthetic tenant and resource identifiers with redacted claim labels.
Trace identity to policy
Capture selected identity, environment, token scope and role labels, resource lookup, endpoint policy result, response, and local branch. Compare first divergence between allowed and denied cases. Record client and policy revisions without copying credentials.
Vary one authority input
Change only identity, role, scope, tenant, resource, or operation in separate runs. Compare results and side effects. If role and tenant both explain the denial, name the missing policy observation rather than granting both.
What to carry forward
The investigation is ready when paired operations show identity, claims, resource, policy, and local result boundaries. Recommend one narrow role or mapping change. Leave authority unresolved where the policy owner or tenant evidence is unavailable. Keep tenant evidence beside the policy trace.
Technical background: OpenAI documentation.
Keep the decision with the work.
Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.
Create an account See the product workflow