Runbook §2.5. Super-admin control test: §2.4. Issue #24.
Verified against reality: YYYY-MM-DD by NAME
prod config.| Service | Principal (named person) | Role | MFA | Notes |
|---|---|---|---|---|
| Google Workspace | TODO | Super-admin (OFM) | TODO | Can suspend any account, incl. Developer |
| Google Workspace | TODO | User (Developer) | TODO | No admin console access |
| GitHub org | TODO | Owner (OFM) | TODO | |
| GitHub org | TODO | Member (Developer) | TODO | |
| Cloudflare | TODO | Super Administrator (OFM) | TODO | |
| Cloudflare | TODO | Administrator (Developer) | TODO | |
Vault — prod | TODO | Read+write (OFM) | TODO | |
Vault — prod | TODO | Read-only (Developer) | TODO | Write denied — see test below |
Vault — dev | TODO | Read+write (Developer) | TODO | |
| Stedi (production) | TODO | Key holder (OFM only) | TODO | Developer has no prod key |
| Stedi (sandbox) | TODO | Key holder (Developer) | TODO |
prodPaste the exact command and its denial output.
TODO — command + denied response, with date
Create a throwaway Developer grant, suspend it via OFM super-admin, confirm lockout, paste evidence.
TODO — steps + confirmation of lockout, with date