Step 1Map who can deploy
People, roles, tokens and pipelines that can reach each environment.
ATALAIAWho can push to production right now?
PLATFORMThirty-one people, and four tokens nobody remembers creating.
Leaves the room31 people and 4 tokens can reach prod
Step 2Define the gates
What must be green at each step, and who signs.
ATALAIAEvery step gets a gate. QA needs tests green, prod needs an approver role.
DEV LEADA role, not a named person? People go on holiday.
ATALAIAA role. Two people hold it, and the pipeline checks it.
Leaves the roomDEV → QA → STAGING → PROD, gates defined
Step 3Attach the evidence
Scans, tests and review status shown at the moment of approval.
MANAGERWhen I approve, what am I actually looking at?
ATALAIAScans, tests and pentest status, on the approval itself.
MANAGERPentest green, tests green. Approved for the 14:00 slot.
Leaves the roomEvidence on the approval
Step 4Review the keys
Access to production reviewed before it ships, and on a schedule.
PLATFORMAnd break-glass, when prod is on fire?
ATALAIAIt works, it expires in two hours, and it's reviewed the next morning.
Leaves the roomBreak-glass: 2 hours, logged, reviewed
- PLATFORM
- ATALAIA
- DEV LEAD
- MANAGER