What do you do when you discover an administrator has been making changes directly in production?
Suggested answer
I separate the technical remediation from the process conversation, and I do the technical part first.
Find them — Setup Audit Trail for the event record of what changed and by whom within its retention window, and a metadata comparison between production and the repository for the current-state difference, which catches anything the audit trail no longer holds.
Retrofit them — commit the changes into version control and apply them to the lower environments, so the source of truth and the environments match production again. Until that is done, the next release will silently overwrite whatever the business has come to depend on.
Then the process conversation, and I try to start it without blame. If the pipeline could not deliver an urgent change in an acceptable time, the administrator behaved rationally and the pipeline needs a governed emergency path. If the pipeline was fine and the process was simply bypassed, that is a different conversation — but I want to know which one I am having before I open it.
Longer term I want ongoing detection rather than discovery by accident: the audit trail reviewed on a cadence, and an automated production-versus-repository comparison that reports differences to the release owner with a defined action — every difference is either retrofitted or reverted, with the decision recorded.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.