Keep the lesson for the next incident
Document operation authority
Record method, endpoint, resource, tenant, required role and scope, expected denial, identity label, environment, and owner. Define safe behavior for missing, wrong, and expired authority without copying credential material. Keep the operation-to-role mapping readable.
Keep role fixtures
Retain allowed, denied, wrong-tenant, wrong-resource, insufficient-role, and revoked-role cases with synthetic identifiers. Store expected state and side-effect limits. Include the original denial so role or client changes have a concrete comparison.
Review access signals
Watch new denials, unexpected allowed operations, role changes, identity swaps, and cross-tenant lookup attempts by environment. Assign an owner and threshold. Close the follow-up only when matrices cover the operations the account actually performs.
What to carry forward
Close learning with operation authority, fixtures, identity ownership, and review signals. Keep policy and tenant assumptions explicit. The durable outcome is a narrow permission request with evidence, not a permanently broad credential. Review role changes before broadening any operation safely.
Technical background: OpenAI documentation.
Keep the decision with the work.
Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.
Create an account See the product workflow