LaraDep Documentation
You are reading Managed mode
Roles, security and access control in managed mode
How to set role model, access control and decision points in managed mode: stability, control and audit trail.
Access and access governance in managed mode
Managed mode is often chosen for speed, but it still requires strict governance. Without clear roles and permission model, the same process can become risky and non-auditable.
Purpose and assumptions
- Purpose: establish predictable ownership for every change: who requested, who approved, who executed, who verifies.
- Prerequisites: an operational workspace model is in place and team members understand run history semantics.
- What you need: role matrix, change categories, and communication channel for incidents and windows.
Role model
- Change owner — proposes and prepares the change scope.
- Approver — confirms readiness and grants deployment permission for high-impact runs.
- Operator — executes the run through the standard flow.
- Reviewer — validates results and signs off outcomes in run notes.
Configuration steps
- Classify change categories by impact: low, medium, high.
- Set minimum permissions for each workspace role and avoid over-privileged defaults.
- Link review path so high-impact changes cannot skip approval.
- Define change windows and expected communication format.
- Require run notes before marking a deployment complete.
Validation checklist
- Are roles applied consistently across workspaces?
- Does each critical run include change owner and approver?
- Are unplanned windows documented with a technical lead and impact rationale?
- Are sensitive run notes reviewed and archived?
- Is access revocation and periodic audit part of your routine?
Common mistakes
- Skipping role review and relying on implicit trust.
- One person handling request, approval and execution for all high-risk changes.
- Postponing run notes until after rollback or after incident.
- Allowing long-lived elevated roles without periodic review.
Next steps
- Move to managed operations for routine cadence and operational checklist.
- Validate governance details in managed governance checklist.
- Use first deployment checklist for your baseline baseline.
- Review mode decisions in managed vs self-hosted.
Next step: Open the managed onboarding checklist before your first production change.