Ch 1 · Fundamentals
New: dry-run mode
05 / 44

Org policies now ship with a dry-run mode.

Observe a policy's real blast radius against live traffic before ever enforcing it.

1. AttachA stricter policy, in a separate dry-run slot
2. ObserveGCP logs what it would have blocked, blocks nothing
3. ReviewReal violations surface over 1-2 weeks of traffic
4. EnforcePromote to live, only once the blast radius is known

Unchanged

IAM answers "who," org policy answers "what's allowed to exist" — a full-IAM owner still can't violate an active policy

Real incident

A dry-run key-blocking rollout surfaced a personal project with a leaked service account key nobody knew existed