landing-zone-identity

Type: regulative

Decision

A landing zone must have a single managed identity, shared across all its workflows, jobs, and service integrations.

Why

Without a single identity, every new capability multiplies the permission surface through RBAC and OIDC sprawl.

Violations

Anchor

no-platform-ops

Implements

Files

Links

← Back to knowledge graph