landing-zone-identity

Type: decision

Decision

Each landing zone has a single managed identity — shared across all its workflows, jobs, and service integrations.

Why

Without a single identity, every new capability multiplies the permission surface — RBAC and OIDC sprawl.

Violations

Links

← Back to knowledge graph