Credential scopes
The production gate
The path to production carries the most friction, by design. Each infrastructure write goes to the IT lead, who approves or denies it. Approval issues a scoped, time-limited credential, the action runs, and every step is logged.
Running the estate without a devops hire
About 98% of the AWS and on-premise estate is maintained and monitored by ICA. No in-house devops team sits behind it, and every change that touches production still goes through the gate above.
- 300 Kubernetes pods running in production
- 20 services across AWS and on-premise
- No dedicated devops or infrastructure hire
Lesson learned
The data analytics agent came too early. Each agent ran standalone, context broke between them, and the knowledge that mattered stayed in the IT leads' own heads. Getting the agent harness right changed that. One shared knowledge graph cut the human dependency out of the loop, and agents carrying more context return far more accurate results.