Core flow
- validate identity and resource tenant;
- deny cross-tenant access before evaluating role;
- apply explicit role/action policy with default deny;
- require administrator role and reason for membership changes;
- record tenant-scoped audit evidence;
- surface hardening findings for risky configuration.



