Change Data Capture Pipeline  ·  View 20 of 21  ·  Assurance

Identity and Access Flow

A privileged action the platform is allowed to refuse, and why that refusal is the control.

Editable source SVG draw.io All views
Platform SRE Operator API Cloud IAM Control plane Capture plane Audit log 1. POST /tables/orders:resnapshot 2. verify identity and role 3. cdc.tableOperator granted 4. check preconditions 5. retention headroom, no snapshot in flight 6. refused: would exhaust WAL retention 7. record attempt and refusal 8. retry with source budget raised 9. start chunked snapshot at LSN 10. chunk progress 11. record action, actor, target Identity and Access — Authorising a Re-Snapshot A privileged action the platform can refuse is the point: the capture plane never takes an operator's word for retention headroom. v 1.0 · owner Data Platform Architecture · date 2026-10

Decisions

  • Authorisation is role-based and coarse: a re-snapshot or allow-list change is privileged; a lag query is not.
  • The control plane re-checks preconditions independently of the operator's intent — retention headroom and no snapshot in flight — and refuses rather than queues (ADR-03).
  • Every attempt, refusal and action is recorded in an append-only audit log retained 13 months.

Why this flow

  • A re-snapshot is the most dangerous safe-looking button in the platform: it reads a whole table from a live source.
  • Showing the refusal path rather than the happy path is the point of the view.

Omitted

  • Service-to-service workload identity on every internal call, which is assumed throughout and shown as a zone property on view 19.