Skip to content

Operations

This section covers the operational processes that keep our nomenclature consistent and our access model secure. Every group, role, and engagement follows the same lifecycle pattern: create, operate, retire.

Every resource in the nomenclature system follows the same three-phase lifecycle:

  1. Justify — Document the need (ticket with purpose, scope, owner).
  2. Name — Follow the canonical pattern for the resource type.
  3. Configure — Apply type-specific settings (security label, membership, posting rules).
  4. Wire — Connect to parent groups, drives, and downstream consumers.
  5. Evidence — Screenshot/commit settings to the change ticket or IaC repo.
  • Quarterly reviews — Verify owners, members, settings, and compliance.
  • JML events — Update memberships when people join, move, or leave.
  • Drift detection — Automation flags deviations from canonical settings.
  1. Freeze — Disable posting, remove from ACLs.
  2. Export — Archive per retention policy.
  3. Hold — Keep locked for audit period (typically 1 year).
  4. Delete — Remove after hold period.
  • Lifecycle — JML processes, change control, and cadences
  • Governance — Tenant model, compliance, and security invariants