Decide where the work belongs
Map operation consequence
For each denial, list method, resource, tenant, workflow, current state, and whether work is pending or can be retried safely. Compare real downstream use rather than status counts. Keep identity and resource labels attached to each item.
Compare least-privilege options
Assess correcting tenant mapping, selecting the right service identity, adding one role, changing endpoint use, or reviewing the operation. Record authority and rollback. Do not grant a broad role when a resource binding or wrong credential explains the denial.
Set an access queue
Queue blocked mutations and cross-tenant uncertainty first, then shared identity or role drift and isolated reports. Set owner, review date, evidence threshold, and removal plan. If role meaning is unclear, prioritize the operation-to-role comparison.
What to carry forward
Return an access queue with operation effect, tenant and role evidence, least-privilege containment, owner, and acceptance proof. Escalate cross-tenant risk and unknown writes. Keep ranking provisional when service identity claims are unverified. Keep authority ambiguity visible to the owner.
Technical background: OpenAI documentation.
Keep the decision with the work.
Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.
Create an account See the product workflow