Meaning
An operational security policy requires employees who manage core developer platform infrastructure to cease active work and lose access to production environments during their notice period. Implementing a policy for garden leave platform personnel protects the integrity of the delivery pipeline from potential insider action. These individuals possess administrative credentials and deep knowledge of the cluster security architecture, making their exit a sensitive transition.
The policy ensures they remain employed but do not interact with systems or codebase.
Transition Protocol
Structured handovers must occur before an administrator leaves active duty to preserve operational continuity. When garden leave platform personnel begin their transition, their responsibilities are transferred to remaining team members through a formal checklist. This transition includes documenting ongoing tasks, transferring secrets ownership and auditing recent configuration changes.
It preserves institutional knowledge while isolating the departing worker from the active system.
Access Revocation
Securing the platform boundary requires immediate action to deactivate all active credentials and sessions. For garden leave platform personnel, the IT department terminates VPN access, console logins and API tokens on the first day of the notice period. This action must be automated to ensure no dormant accounts remain.
It prevents both accidental and intentional system modifications during the sensitive notice period.
Threat Mitigation
The potential damage from a disgruntled platform engineer with high-level access is immense, ranging from database deletion to pipeline sabotage. Enforcing garden leave platform personnel rules is a mitigation strategy that prevents these risks. The cost of calling this protocol late is high, potentially allowing an individual to implant backdoors or extract sensitive source code before access is pulled.
However, implementing it means paying salaries to non-producing workers, a cost organizations accept to ensure the safety of their software supply chain.