A proposed four-day workshop on effective access
Participants need basic workload and identity concepts. We use a bounded lab model and explicit expected permissions instead of assuming that every shared platform has the same tenant requirements.
Day 1
Workloads, identities, and required actions
Explain application resource scope, service accounts, and the operations needed for a release. Define positive and negative checks before changing permissions.
Hands-on exercises
- Map a sample identity to its required workload actions.
- Compare an authorization denial with an unrelated workload failure.
Day 2
Templates and control-plane permissions
Connect rendered resources, roles, bindings, and admission behavior. Identify the scope and effective identity behind each API decision.
Hands-on exercises
- Investigate an unintended permission or missing required action.
- Verify a bounded role change using explicit request cases.
Day 3
Network policy and runtime paths
Trace service discovery, policy selectors, ingress and egress, and the installed enforcement mechanism. Keep network and API authorization observations separate.
Hands-on exercises
- Compare an intended connection with a path that must be rejected.
- Diagnose a policy selection or enforcement assumption.
Day 4
Data access and repeatable verification
Examine secrets, storage, resource sharing, and permissions as parts of the workload boundary. Verify that the selected controls preserve the application's legitimate behavior.
Hands-on exercises
- Repeat application and data-access checks after a control change.
- Record identities, requests, expected decisions, and remaining scope limitations.
Your tenant model, controls, and verification responsibilities can shape the agenda. Get in touch to tailor the workshop to your team's work.