Production Access
Who can touch production, with what privilege, for how long — and what to do about the emergency where someone genuinely must.
Who can reach production, what they can do there, and why the answer is a set of specific approved capabilities rather than a single administrator role.
The operational form of a security principle: permissions sized to the task, scoped to the resources, and bounded in time — with an honest account of what that costs during an incident.
Emergency elevated access that is explicit, audited, short-lived and automatically revoked — the answer to "but what if we need admin during an incident".
Sometimes an emergency requires acting by hand. The damage is not the manual change — it is the permanent, undocumented divergence between production and the code that is supposed to describe it.
The periodic check that the people and services with production access are the ones who should have it — a backstop for expiry, not a substitute for it.