docs(adr): Add BU-user ArgoCD UI access model to ADR-002 - #8553
Merged
Merged
Conversation
ADR-002 specified deployment-side tenant isolation but never defined how BU engineers reach the ArgoCD UI. Document the two-layer access model (Identity Center global VIEWER for UI entry, per-BU AppProject roles for Application visibility), the BU-to-identity-group mapping keyed on the GitHub business-units parent groups, and the group-tier asymmetry versus the product.yaml AWS/EKS access path. Records the four onboarded BU group mappings (with a reviewer-confirm callout on octo and cd, which are inferred from child-team naming) and the anticipated future BU groups, plus the operational dependency that squad teams must be nested under their BU parent to inherit UI access. Part of #8548
David Elliott (davidkelliott)
approved these changes
Sep 24, 2026
David Elliott (davidkelliott)
left a comment
Contributor
There was a problem hiding this comment.
Verified that BU parent GH teams are a strategic decision and can be used going forward.
William Ngufor (nguforw-moj)
deleted the
docs/adr-002-argocd-bu-access
branch
September 24, 2026 10:14
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ADR-002 specified deployment-side tenant isolation but never defined how BU engineers reach the ArgoCD UI (the gap behind #8548).
Documents the two-layer access model (Identity Center global
VIEWERfor UI entry, per-BU AppProjectrolesfor Application visibility), the BU-to-identity-group mapping keyed on the GitHubbusiness-unitsparent groups, and the group-tier asymmetry vs theproduct.yamlAWS/EKS path.Records the four onboarded BU group mappings (with a reviewer-confirm callout on
octo/cd, inferred from child-team naming) and the anticipated future BU groups, plus the operational dependency that squad teams must be nested under their BU parent to inherit UI access.Implemented in ministryofjustice/modernisation-platform-environments#19301.
Part of #8548