The review follows data and control paths through the selected environment: identities, ingress, workloads, storage, queues, administration, observability, vendors, and recovery. We compare intended architecture with the configuration and operational evidence that is available.
Attention goes to systemic issues such as broad trust zones, implicit network access, weak administrative paths, unmanaged secrets, missing tenant isolation, insufficient recovery boundaries, and security controls that exist only in documentation. Findings are framed around the business workflow they could interrupt.
Recommendations distinguish a design correction from a configuration fix and from a process owner. Each item includes a practical verification step, so engineers can tell when a hardening action is complete and leaders can see which risks remain accepted.
The assessment is not a penetration test and does not silently change production. It is a decision-quality review that can guide implementation, a later vulnerability assessment, or a more focused threat model.