Skip to content

Identity P1.2: Workforce role catalog (reach × power roles as artifacts) #887

Description

@gangster

Part of #884. Strategy §2.2. P1.1 grants reference roles that must exist as real artifacts. Distinct from #361–363 (product-scoped developer roles) — this is the non-builder catalog.

Scope

  • Define the catalog: developer · team-admin · viewer · platform-operator · auditor · access-admin · break-glass, each with its reach × power and standing-vs-activation mode.
  • Map each AWS-reach role to an Identity Center permission set (managed + inline policy + session_duration) — grounding confirmed: the platform already uses permission sets.
  • Map each to the corresponding Keycloak role/group for app access.
  • Meta-governance ([must], §3.6): catalog changes go through blast-radius analysis (a model change re-permissions many principals at once).

Done when: the catalog is defined as code and is what P1.3/P1.4 generate against.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions