Health Check & Service Discovery  ·  View 20 of 21  ·  Assurance

Identity and Authorisation Flow

A privileged action the platform is allowed to refuse, and why the refusal is the control.

Editable source SVG draw.io All views
SRE on call Admin client Workload / human identity Policy API Budget guard Evaluator Audit log 1. force instance ineligible 2. assume break-glass role 3. scoped, 15 min 4. override + justification 5. authz: may deny this service? 6. check disruption budget 7. refused: floor is 50% 8. attempt, actor, refusal 9. 429 + the floor it hit 10. evacuate the zone instead 11. declared evacuation 12. shift topology preference 13. policy change recorded 14. accepted, reversible in one step Identity Flow — An Override The Platform Is Allowed To Refuse The refusal is the control. An operator who can always remove capacity is a denial-of-service path with a badge. v 1.0 · owner Reliability Architecture

What this flow proves

  • The break-glass role is scoped and time-boxed, and the attempt is audited whether or not it succeeds.
  • The budget guard refuses the override and returns the floor it hit, so the operator learns something rather than retrying.
  • The accepted path — a declared evacuation — is reversible in one step, which is why it is the safer instrument.

Assumptions

  • 15-minute credential scope; override attempts rate-limited per actor per service; justification is a required field.

Risks

  • An operator who can always remove capacity is a denial-of-service path with a badge. The refusal is load-bearing, not advisory.