Four engineers share one unlimited administrative role over a secret store — when an audit asks who could have read the payments password, what can you say?
answer
- who could have, not who did
- a complete record can still exonerate nobody
- one role, four people, no elimination
- split operate, change rules, read values
- the escape path becomes a recorded change
basics
~20 sOnly that all four could have, at any time. A complete record still shows which reads happened, but with one unlimited role nobody can be ruled out — and if that role can also change the rules, its holders could have granted themselves the read quietly.
solid answer
~50 sThe audit's question is not only *who did* but *who could have*, and separation of duties is what makes the second question answerable. With one unlimited role held by four people, the suspect set is those four for every value, forever, and if the role also changes the rules and administers the record, they could have arranged the access and the evidence. The record is not worthless — it still shows what was requested and by which identity — but it exonerates nobody. The fix is to split the role into operating the service, changing the rules, and reading values, and to keep any one identity from holding two. That does not make an administrative read impossible: whoever changes the rules can still grant themselves read. It converts a silent read into a recorded change someone must make first, and that is the property worth paying for.
go deeper
Recall that an unlimited administrative role means everyone who holds it is a possible reader of every value, and that a shared login records the role rather than the person.
Explain the difference between what a record can show — which identity asked for what, and when — and what only the grants in force can answer: who was capable of reading it at all.
Show the operating consequence: scope an incident by the role's reach rather than the intruder's activity, and alert on rule changes over high-value credentials rather than on routine reads.
Own the sizing: how many people must act alone at three in the morning, what an audit must be able to answer, and the honest admission that the split buys a loud recorded step rather than impossibility.
## The question is "who could have", not "who did" When an external audit or an internal investigation asks about a stored credential, it asks two questions, and the second one is the hard one: - **Who read this value?** A store's own record answers this: which identity asked, for which name, at what time, with what result. - **Who could have read it?** No record answers this. It is answered by the set of grants that were in force, and by whether one person could have held more than one of them. Separation of duties exists for the second question. Its value is not that it produces more evidence; it is that it makes **elimination** possible. If the payments password can only be read by the payments service's identity and by two named people, then everyone else is ruled out by construction, and the investigation is small. If one unlimited role covers everything and four people hold it, nobody is ruled out and the investigation has no floor. ## Why a perfect record still exonerates nobody Assume the record is complete, accurate and tamper-evident — what makes it so is a subject of its own, and assume the best case here. With one unlimited role: - **The suspect set equals the role's membership**, for every value, for the whole period the role existed. That set does not shrink with better evidence. - **If the identity is shared**, the record names the role, not the person, and no amount of retention fixes an attribution that was never captured. - **If the role can change the rules**, a holder could have granted themselves a read, taken it, and removed the grant. The record shows a rule change, which is evidence — but only if someone was watching rule changes, and only if the record of changes is outside the role's own reach. - **If the role administers the record itself**, the last assumption fails too, and the record's completeness stops being something you can assert to an outsider. The practical consequence arrives at the worst moment. When one of the four has a laptop compromised, the blast radius is every value the role could reach, because nothing distinguishes what that person did from what the role was capable of. The remedy is to replace everything in scope — which is an estate-wide event caused by a rights design, not by the intrusion's actual reach. ## Splitting the role | Right | What it covers | Who should hold it | |---|---|---| | Operate the service | restart, replicate, back up, upgrade, observe | the platform team's operator identity | | Change the rules | who may read or write which values | a small, separate set, with changes reviewed | | Read values | the contents of a stored credential | the consuming workload, and the owning team | The rule that makes the table worth anything: **no identity holds two rows**, and membership of the second row is not automatically the same people as the first. ## The escape path, and what the split really buys Be honest about the limit, because an interviewer will push here. Whoever can change the rules can grant themselves a read. The split does not make an administrative read impossible, and claiming that it does is the error that discredits the whole argument. What it does is change the **shape** of that read: 1. It stops being invisible. The read is preceded by a rule change, which is a different kind of event from a routine read, and a much rarer one. 2. It becomes attributable, provided identities are per-person rather than shared. 3. It becomes alertable and reviewable, because a rule change over a high-value credential is a sensible thing to alarm on, and a routine read of that same credential by a service is not. 4. It becomes explainable after the fact: the investigation has a specific event with a time, an actor and a before-and-after, rather than an open period. That is the trade a lead is buying: not prevention, but a step that is loud, rare and attributable in front of what used to be silent. ## The cost, and the judgment The cost is real and lands on availability. Fewer people can act alone, some repairs wait for a second person, and a badly-drawn split locks the team out of its own store — which is why a pre-authorised emergency path exists as a separate design, with its own alarm and its own review. So the judgment a lead owns is a sizing problem: how many people must be able to act at three in the morning, what an audit and an investigation must be able to answer, and how much of each you are willing to trade. In a four-person team the answer is rarely five roles; it is more often two identities per person — an everyday one that cannot read values, and a rarely-used one that can and that announces itself when used.
- If whoever changes the rules can grant themselves read anyway, what has the split achieved?It converts a silent read into a recorded rule change that has to happen first. That event is rare, attributable to a person, worth alerting on, and explainable afterwards with a time and a before-and-after — none of which is true of a routine read by an unlimited role. The split buys visibility and attributability, not impossibility.
- One of the four has their laptop compromised. Why is the response so much larger than the intrusion?Because the role's reach, not the intruder's activity, defines the scope. With an unlimited role nothing distinguishes what that person did from what the role could do, so every value it could reach has to be treated as exposed and replaced. Narrower grants make the same incident a scoped replacement rather than an estate-wide one.
- A four-person team cannot staff five separate roles. What is the workable version?Two identities per person rather than five roles per team: an everyday identity that operates the service and cannot read values, and a rarely-used one that can, which announces itself when used and is reviewed afterwards. The separation is between the identities and their records, which is what makes elimination possible, not between the head-count.
If four guards share one badge, the door log still records every entry faithfully — it simply cannot place any of the four somewhere else. Separation of duties is what lets you rule people out; it does not make the log longer.
saying these in an interview costs you the question
- Says a complete audit record settles who could have read the value
- Claims splitting the role makes an administrative read impossible
- Treats one shared administrative login as fine because activity is recorded
- Assumes separation of duties costs nothing at three in the morning
- Thinks naming an actor in the record is the same as ruling others out