I'm setting up my first real data pipelines (Airbyte → BigQuery → dbt) and hit the IAM wall. My team wants "just-in-time" access for production DBs.
But from my seat, it looks like we just traded a permanent role for a Slack approval queue. Same people, same access, just slower. 😅
* Is the security gain from the *delay*?
* Or are we just adding process without actually reducing the attack surface?
Example: I needed to debug a live sync. Instead of having `roles/bigquery.dataViewer`, I had to:
1. Request in Okta
2. Wait for lead approval
3. Remember to revoke in 4 hours (I forgot once)
The config didn't change the *what*, just the *when*. Is that normal? What should I be looking for in a JIT tool to feel like it's actually safer?
My naive thought: Shouldn't it be more like scoped, auto-expiring credentials based on a ticket/PR? Almost like:
```python
# Pseudo-code fantasy
access_token = request_entitlement(
resource="project-dataset",
reason="PR#42 - Fix broken transformation",
scope="SELECT",
expires_in="1h"
)
```