Night Mode LabsBlue Book
Evidence Requests

Access Request Matrix

Use the access request matrix to request the minimum access needed for discovery and implementation. Start read-only, then request privileged access only for specific tasks.

Access levels

LevelUse
Read-onlyDiscovery, inventory, evidence review, and dashboards.
OperatorRunning approved diagnostics or non-destructive actions.
DeployerTriggering deployments, rollbacks, or environment changes.
AdminManaging platform configuration, identity, or policy.
Break-glassEmergency access with approval, logging, and review.

Common access requests

SystemDiscovery accessImplementation access
Source controlRead repositories and pull requestsBranch and pull request permissions
CI/CDRead pipeline history and configsTrigger approved workflows
CloudRead inventory, IAM, logs, and costsScoped IaC or deployment roles
ObservabilityRead dashboards, logs, traces, alertsUpdate dashboards and alert rules
SecretsReview metadata and access patternsScoped secret creation or rotation
Incident toolingRead incidents and postmortemsCreate or update incident records

Request guidance

  • Tie every request to a task or deliverable.
  • Prefer groups or roles over individual grants.
  • Use time-bound access for implementation.
  • Avoid shared accounts.
  • Record approval and expiry.
  • Revoke consulting access during closeout.

Watchouts

  • Discovery can often proceed with read-only access.
  • Admin access should not be the default workaround for unclear roles.
  • Screenshots are not a substitute for access to systems of record.

On this page