Aglet

Investigate service account role and scope mismatches

Investigation should show why one operation is denied while another works. Build allowed, denied, wrong-tenant, and wrong-identity fixtures, then trace claims and resource policy. Keep missing role, tenant mismatch, endpoint policy, and stale configuration as competing hypotheses for one operation and environment.

Build a useful investigation brief

  1. Build permission fixtures

    Create one allowed read, one denied write, one wrong-tenant resource, and one similar identity with insufficient role. Record expected result and authority before execution. Use synthetic tenant and resource identifiers with redacted claim labels.

  2. Trace identity to policy

    Capture selected identity, environment, token scope and role labels, resource lookup, endpoint policy result, response, and local branch. Compare first divergence between allowed and denied cases. Record client and policy revisions without copying credentials.

  3. Vary one authority input

    Change only identity, role, scope, tenant, resource, or operation in separate runs. Compare results and side effects. If role and tenant both explain the denial, name the missing policy observation rather than granting both.

What to carry forward

The investigation is ready when paired operations show identity, claims, resource, policy, and local result boundaries. Recommend one narrow role or mapping change. Leave authority unresolved where the policy owner or tenant evidence is unavailable. Keep tenant evidence beside the policy trace.

Technical background: OpenAI documentation.

Keep the decision with the work.

Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.

Create an account See the product workflow