Part of #884. Strategy §2.2. P1.1 grants reference roles that must exist as real artifacts. Distinct from #361–363 (product-scoped developer roles) — this is the non-builder catalog.
Scope
- Define the catalog:
developer · team-admin · viewer · platform-operator · auditor · access-admin · break-glass, each with its reach × power and standing-vs-activation mode.
- Map each AWS-reach role to an Identity Center permission set (managed + inline policy +
session_duration) — grounding confirmed: the platform already uses permission sets.
- Map each to the corresponding Keycloak role/group for app access.
- Meta-governance (
[must], §3.6): catalog changes go through blast-radius analysis (a model change re-permissions many principals at once).
Done when: the catalog is defined as code and is what P1.3/P1.4 generate against.
Part of #884. Strategy §2.2. P1.1 grants reference roles that must exist as real artifacts. Distinct from #361–363 (product-scoped developer roles) — this is the non-builder catalog.
Scope
developer·team-admin·viewer·platform-operator·auditor·access-admin·break-glass, each with its reach × power and standing-vs-activationmode.session_duration) — grounding confirmed: the platform already uses permission sets.[must], §3.6): catalog changes go through blast-radius analysis (a model change re-permissions many principals at once).Done when: the catalog is defined as code and is what P1.3/P1.4 generate against.