← Banking infrastructure: fundamentals and production decisions
09 / 10 · 60 MIN

Access, secrets, and controlled maintenance

Define task-scoped access, track secret consumers, and verify maintenance through the functional outcome.

Translate a task into a grant

In a fictional funds project, an operator needs to restart one instance during a change. The access request should identify person or workload, action, resource, window, and decision reference. Reading does not imply export, and restarting one application does not grant administration of the entire environment. This lesson’s model compares those fields exactly and uses exclusive expiry. It is a teaching contract rather than an AWS IAM evaluator. In an actual platform, policies, sessions, delegation, and conditions can interact; acceptance needs to observe the path the operator actually uses.

Demonstrate granting and withdrawal

The matrix should include an allowed case and denied cases. In the exercise, operator A restarts funds-1 inside the window; another action, resource, person, or reference is denied. A request at the expiry instant also fails. After the change, requesting revocation is different from demonstrating lost capability. If the action remains possible, investigate alternative grants, sessions, and platform mechanisms. Record outcomes and the identity used. Do not share a more privileged account to bypass denial: that changes scope and weakens attribution of what actually happened.

Manage every consumer of a secret

A secret may serve an online application, a batch, and a support tool. Creating a new value in the vault is only one step. Identify consumers, update the intended mechanism, demonstrate functionality, and address the previous value under the rotation plan. If exposure occurred, response needs containment and usage assessment rather than merely deleting the file where it appeared. Where applicable and authorized, overlap needs boundaries and exit criteria. In AWS, roles with temporary credentials are a recommended alternative for compatible workloads; do not assume a personal key is a sustainable dependency.

Prepare emergency access and attributable evidence

Recovering an identity service can depend on a secret available only through that service. This cycle needs an emergency path designed before the incident with custody, coverage, authorization, and review. The exercise defines no emergency passwords and authorizes no actual access. The report should connect actor, action, resource, time, reference, and decision. Keep the secret value out of shared evidence. Use synthetic training data and distinguish authentication, authorization, and auditing: proving who requested something does not grant the action, and storing a log does not establish correct policy enforcement.

Verify maintenance through use

The teaching inventory has three applications. App1 received v2 but runs v1. App2 runs v2 but fails the functional flow. App3 runs v2 and passes that flow. Only app3 meets the stated criteria. Record installation, activation, and acceptance as separate milestones. For obsolescence, include supported version, compatibility, effort, window, and contingency in funded scope. A temporary exception needs ownership, mitigation, and review; it does not turn old software into fixed software. Priority should consider exposure and impact as well as installation convenience or quickly closing a dashboard task.

Execute the fictional contract and discuss limits

Save the code as run.py and execute python3 run.py --output evidence.json. The program contacts no services and uses no credentials. It compares exact grants, maintenance states, costs, and retirement conditions using invented data. Its result is repeatable because it does not measure variable infrastructure. Explain which observations would need reproduction in an authorized environment and who would accept them. For APS handover, deliver the action matrix, consumer inventory, functional outcomes, and time-bounded pending work. Executing the program does not replace shift training or independent specialist review of the operating design.

"""Original offline decision model. No IAM engine, cloud invoice, or supplier exit.
Run: python3 run.py --output evidence.json
"""
import argparse
import hashlib
import json
import math
import platform
from fractions import Fraction
from pathlib import Path


def allowed(grant, request, now):
 # Explicit fictional contract: exact action/resource, exclusive expiry.
 return bool(grant['active'] and grant['start'] <= now < grant['expires']
 and request['actor'] == grant['actor']
 and request['action'] in grant['actions']
 and request['resource'] in grant['resources']
 and request['ticket'] == grant['ticket'])


def allocate(direct, shared, weights):
 if set(direct)!= set(weights) or shared < 0 or min(direct.values) < 0 or min(weights.values) < 0 or sum(weights.values) <= 0:
 raise ValueError('invalid allocation inputs')
 total = sum(weights.values)
 return {k: Fraction(v) + Fraction(shared * weights[k], total) for k, v in direct.items}


def run:
 checks = []
 def check(name, actual, expected):
 assert actual == expected, (name, actual, expected)
 checks.append(dict(name=name, actual=actual, expected=expected, passed=True))
 grant = dict(actor='operator-A', actions=['restart'], resources=['prod-funds-1'], ticket='CHG-DEMO', start=10, expires=20, active=True)
 request = dict(actor='operator-A', action='restart', resource='prod-funds-1', ticket='CHG-DEMO')
 check('scoped action inside window', allowed(grant, request, 15), True)
 check('before approved window', allowed(grant, request, 9), False)
 check('exclusive expiry boundary', allowed(grant, request, 20), False)
 for field, value in [('actor','operator-B'), ('action','export'), ('resource','prod-other-1'), ('ticket','CHG-OTHER')]:
 check('different ' + field + ' denied', allowed(grant, {**request, field:value}, 15), False)
 check('revoked grant is denied before expiry', allowed({**grant,'active':False}, request, 15), False)
 check('unapproved extension remains denied', allowed(grant, request, 21), False)
 evidence = dict(actor=request['actor'], action=request['action'], resource=request['resource'], ticket=request['ticket'], decision='allow', timestamp=15)
 check('attributable audit fields', sorted(evidence), ['action','actor','decision','resource','ticket','timestamp'])
 check('no secret value in audit contract', any(k in evidence for k in ['password','token','secret']), False)
 inventory = [dict(id='app1', expected='v2', installed='v2', running='v1', functional=True), dict(id='app2', expected='v2', installed='v2', running='v2', functional=False), dict(id='app3', expected='v2', installed='v2', running='v2', functional=True)]
 complete = lambda x: x['installed'] == x['expected'] == x['running'] and x['functional']
 check('installed package alone insufficient', complete(inventory[0]), False)
 check('running version alone insufficient', complete(inventory[1]), False)
 check('version and function evidence align', complete(inventory[2]), True)
 check('unfinished maintenance inventory', [x['id'] for x in inventory if not complete(x)], ['app1','app2'])
 direct = {'A':6000,'B':3000}
 proportional = allocate(direct, 3000, {'A':2,'B':1})
 check('proportional service allocation', {k:int(v) for k,v in proportional.items}, {'A':8000,'B':4000})
 check('allocation preserves invoice total', int(sum(proportional.values)), 12000)
 equal = allocate(direct, 3000, {'A':1,'B':1})
 check('equal policy changes attribution', {k:int(v) for k,v in equal.items}, {'A':7500,'B':4500})
 check('equal policy does not change invoice', int(sum(equal.values)), 12000)
 check('new full recurring cost', 9000+500+700, 10200)
 check('net recurring saving', 12000-(9000+500+700), 1800)
 check('simple break even excludes overlap', 21600//1800, 12)
 check('old annual cost', 12000*12, 144000)
 check('first year with transition and overlap', 10200*12+21600+6000, 150000)
 check('first year benefit includes all stated costs', 144000-150000, -6000)
 check('whole months to recover transition plus overlap', math.ceil(Fraction(21600+6000,1800)), 16)
 check('old cost per successful item in cents', int(Fraction(12000*100,600000)), 2)
 check('new cost per successful item in cents', int(Fraction(9000*100,300000)), 3)
 check('lower invoice can raise unit cost percent', int((Fraction(3,2)-1)*100), 50)
 check('export duration hours', 600//50, 12)
 check('parallel rebuild and export plus validation', max(600//50,5)+3, 15)
 check('exit margin before sixteen hour target', 16-(max(600//50,5)+3), 1)
 check('half export throughput misses target', max(600//25,5)+3, 27)
 required = ['consumer_release','retention_decision','readability','key_access','access_withdrawal','billing_closed']
 gate = dict.fromkeys(required, True)
 gate['key_access'] = False
 check('archive without keys blocks fictional retirement gate', all(gate.values), False)
 gate['key_access'] = True
 check('complete fictional retirement evidence set', all(gate[k] for k in required), True)
 check('missing billing evidence is not success', all({k:v for k,v in gate.items if k!= 'billing_closed'}.get(k,False) for k in required), False)
 return dict(runtime=platform.python_version,scope='Offline exact-match permission contract, inventory predicates and deterministic cost/exit arithmetic with fictional inputs. Not AWS IAM, a measured migration, a real invoice, a supplier contract or human authorization.',passed=len(checks),checks=checks,runnerSha256=hashlib.sha256(Path(__file__).read_bytes).hexdigest)


if __name__ == '__main__':
 parser=argparse.ArgumentParser;parser.add_argument('--output');args=parser.parse_args
 result=json.dumps(run,indent=2)+'\n'
 if args.output:Path(args.output).write_text(result)
 else:print(result,end='')
IN PRACTICE

App1: v2 installed, v1 active. App2: v2 active, failed flow. App3: v2 active, accepted flow. The model considers only app3 complete.

Common pitfalls

Approval treated as unlimited privilege, a new secret as complete rotation, requested revocation as lost capability, or a copied package as an active fix.

Related topics: Identity, connectivity, and protection · Change, obsolescence, and decommissioning · Cloud, costs, and RUN autonomy

Take this idea with you

Each access and change needs scope, ownership, and an observed outcome; documentation should reflect effective state.

Create account

Reference: Security best practices in IAM · BigSavant banking infrastructure professional assessment2026.10