Cost Allocation & Showback Platform · View 22 of 22 · 7 · Assurance
Decisions
- The scope predicate is resolved server-side from the effective-dated org tree and injected into every query
- A query parameter can never widen scope; an attempt is logged
- Scope is resolved as of the statement's period, so a reorganisation does not retroactively open or close access
Why aggregate rather than deny
- A flat denial teaches nothing and drives people to exported spreadsheets, which is the worse outcome
- Aggregate grain answers 'is my team unusual' without disclosing another team's architecture
Stated assumptions
- MFA is enforced for all human access; machine access uses short-lived workload identity with no static keys
- Group claims from the identity provider name the person, not their scope — scope comes from the org tree