Cloud IAM Governance Playbook & RBAC Matrix
Designed and documented the complete IAM governance framework for an 18-account AWS Organizations environment - the governance foundation that made technical IAM remediation durable.
The technical IAM remediation documented in Project 04 had failed on its first attempt because it lacked a governance layer. Engineers recreated overpermissive roles within weeks because there was no approved access model to reference, no JIT process that was faster than creating a standing role, and no published rationale for why the controls existed. The governance documentation project was the prerequisite that made the second technical remediation attempt stick.
I designed an eight-tier RBAC model mapping each job function to a defined permission set with documented justification for every boundary. The model covered ReadOnly, Developer, DevOps, Security Analyst, Security Engineer, Database Administrator, Cloud Architect, and Break-Glass Admin tiers - each with permitted services, JIT session requirements, approval authorities, and quarterly review frequencies. I published the full design rationale to engineering teams before implementing any restrictions, explaining the threat scenarios each control was designed to address. I also documented the JIT access request process to make it faster than the previous ad hoc approach.