An onboarding drill for a third responder, which found nothing about knowledge and four things about permissions.
1 read access to the log store: granted to a group
the new person was not in
2 the status page: a shared login in a password
manager vault they could not see
3 the DNS provider: still a personal account,
eighteen months after this was first raised
4 ssh: the certificate authority signs for
principals listed per host, and the new principal
had not been added to two of four hosts
none of these are knowledge. all four block a response.
Access is the failure mode that a knowledge-focused onboarding misses entirely, because the person teaching has all of it and cannot see its absence. The DNS account is the one that has survived two attempts to fix it, which is what happens when the fix requires somebody else to change a billing arrangement.