Admin

Admin · Governance

Change, governed.

Every change has a gate, every action has a ledger entry, and the policy matrix decides what runs without a human. Emergency paths exist and leave the loudest trail.

Change queue

  • CHG-5121high riskin-flightEmergency reroute: shift DEN↔KC traffic via ORD→DFWgate:incident-linked (INC-1)
  • CHG-5118medium riskawaiting-goDFW–PHX +200G capacity augment (Meridian)gate:capacity-review
  • CHG-5114medium riskin-flightPlatform 1.32.0 canary → Meridian sim enginegate:canary-policy
  • CHG-5109low riskawaiting-goLHR-CR BGP dampening parameter changegate:network-review
  • CHG-5102medium riskscheduledZitadel IdP cert rotation (all tenants)gate:maintenance-window

Audit ledger

immutable · searchable
sim
  • noc platform success CRIT-4301 · 2026-07-28 12:55 UTC

    lockdown.quarantine · sjc-core2.r02 · vlan 666 QUARANTINE

    Device moved to vlan 666 (QUARANTINE) after anomalous ARP sweep; two-party confirmed.

    lockdown-crit

  • u-bn-rep tenant:Northwind warning EVT-9926 · 2026-07-28 12:50 UTC

    break_glass.open · BG-2201

    Break-glass assist opened on custodial account (reason: SEV2 service loss).

    incident-linked (INC-1)

  • system tenant:Northwind warning EVT-9927 · 2026-07-28 12:51 UTC

    session.flagged · sess-4480

    Session flagged: unrecognized origin during active incident.

    incident-linked (INC-1)

  • u-bn-rep tenant:Briarcliff success EVT-9912 · 2026-07-24 09:10 UTC

    break_glass.open · BG-2198

    Break-glass opened for LOA processing.

    loa-flow

  • u-naas-admin tenant:Briarcliff success EVT-9920 · 2026-07-24 11:02 UTC

    break_glass.close · BG-2198

    Break-glass closed: LOA uploaded, access released.

    loa-flow

  • u-nw-owner tenant:Northwind success EVT-9905 · 2026-07-28 12:40 UTC

    auth.login · sess-4471

    SSO login via Northwind IdP (MFA satisfied).

    sso

  • u-naas-ops platform success EVT-9901 · 2026-07-28 12:34 UTC

    change.approve · CHG-5121

    Emergency reroute approved under incident-linked change gate.

    soc2-change

  • aegis-bot platform success EVT-9898 · 2026-07-27 08:00 UTC

    change.schedule · CHG-5118

    DFW to PHX +200G augment scheduled for capacity review gate.

    capacity-review

  • system tenant:Northwind warning EVT-9890 · 2026-07-28 12:48 UTC

    auth.mfa_challenge · u-nw-ops

    MFA challenge pending for Marco Reyes (TOTP enrollment incomplete).

    mfa-required

  • system tenant:Northwind success EVT-9882 · 2026-07-28 00:05 UTC

    billing.invoice_issued · INV-NOR-1240

    August invoice issued for Northwind Logistics.

    period-close

  • u-bn-rep tenant:Northwind success EVT-9875 · 2026-07-28 12:45 UTC

    delegation.custodial_act · OBA-301

    Custodial action: support ticket opened on behalf of customer.

    custodial-flow

Policy matrix

gate links from the change queue
Framework register →
PolicyCategoryEnforcementScopeGatesControls
Change gatesEvery platform change passes a named policy gate before go (soc2-change, capacity-review, canary-policy).Changeenforcedplatform
  • capacity-review
  • canary-policy
  • network-review
  • maintenance-window
CHG-5121 · CHG-5118 · soc2-change
Break-glass approvalEmergency tenant access requires a second approver and auto-opens an audit row that cannot be edited.AccessenforcedplatformnoneBG-2201 · EVT-9926 · dual-signoff
MFA for privileged rolesPrivileged and operator roles must satisfy MFA before acting; pending enrollment narrows scope.Accessenforcedtenantnoneu-nw-ops pending · mfa-required
Least privilegeRoles grant the minimum permission set for the job; viewer is the default for new joiners.Accessenforcedtenantnonerole catalog · viewer-default
Agentic autonomyAutomated agents may execute within policy gates without a human keystroke, but every action is ledger-accountable.Autonomyadvisoryplatformnoneaegis-bot · CHG-5114 canary
Incident rerouteDuring a SEV1/SEV2, the fabric may reroute under an incident-linked gate and reconcile after close.Incidentenforcedplatform
  • incident-linked (INC-1)
CHG-5121 · INC-1 · incident-linked
Sovereign key custodySovereign-mode providers retain key custody in their own HSM; hosted tenants use the platform KMS.DataenforcedtenantnoneMeridian HSM · provider-sovereignty
Certificate rotationIdP and mTLS certs rotate on schedule before expiry; the next rotation is CHG-5102 (all tenants).DataenforcedplatformnoneCHG-5102 · cert-expiry-watch