@brandont 1 person to do the things & send the logs to a different audit system
1 person to look at the logs and see if the 1st guy is abusing his rights.
For a thing with no administrator, I guess that is like immutable docker containers? Once launched no one has the rights to administer it, except to burn it down and replace it? Still just shifts the focus of the attack from the server to the build server.