Org policies now ship with a dry-run mode.
Observe a policy's real blast radius against live traffic before ever enforcing it.
1. AttachA stricter policy, in a separate dry-run slot
2. ObserveGCP logs what it would have blocked, blocks nothing
3. ReviewReal violations surface over 1-2 weeks of traffic
4. EnforcePromote to live, only once the blast radius is known
Unchanged
IAM answers "who," org policy answers "what's allowed to exist" — a full-IAM owner still can't violate an active policy
Real incident
A dry-run key-blocking rollout surfaced a personal project with a leaked service account key nobody knew existed