androidengineers.Book a session

Identity, permissions, and deployment boundaries

Lab: exercise an enterprise access matrix

exerciseSelf-paced

Assignment

Create synthetic administrator, support, and read-only roles across two tenants, with one service identity and a revoked user.

Build sequence

  1. Define allowed reads, proposals, approvals, and writes for each role.
  2. Test direct APIs, retrieval, cached responses, and queued jobs against the matrix.
  3. Rotate the sandbox service secret and revoke a user during a task.
  4. Write the operational steps for diagnosing identity failures.

Acceptance checks

  • The service identity cannot grant users broader access than their role allows.
  • Revocation affects subsequent protected actions.
  • Audit records distinguish requesting user, approving user, and executing service.

Evidence to keep

Submit the working artifact or decision document described above, the inputs used, and the observed results for every acceptance check. Include one failed attempt and the change you made after investigating it. Label fixture-based outcomes separately from live-system measurements. These artifacts become part of your final portfolio review.

YOUR LEARNING JOURNEY

0 of 119 available lessons completed

Progress saved in this browser. No account needed.
Lab: exercise an enterprise access matrix | Forward Deployed Engineer | Android Engineers