DevOpsDays Barcelona 2026

Access Without Chaos: SQL Guardrails When Everyone's a Builder

Every new SQL database at Mews used to mean a ticket to the Platform team. No controls, no standards, no audit. We didn't even know who had prod access. Here's how we fixed that - for 187 servers, 400+ engineers, and an AI era where everyone is a builder.


Mews had grown organically for over a decade through product-market fit and scale stages without any effective SQL access governance. So it was that we came to this problem with a chaotic mess of access and permissions across our databases. We didn't exhibit least privilege, there was no logging of access, and no shared standards. In many cases, it was guesswork on who had access to each database.

That was the problem worth solving.

The solution came together in layers. We built a centralised Terraform repository as the single source of truth for SQL access configuration. We introduced a PIM self-service model where engineering managers and staff engineers manage their own teams' database memberships - no Platform team involvement needed at runtime. 400+ engineers now operate within a zero-standing-access model: time-limited, justified, fully auditable. Connection strings and local users gave way to managed identity authentication throughout the fleet.

Three cloud-native policies now enforce compliance at the control plane level - resource locks preventing accidental deletion, identity administrator governance, and audit logging routed to a centralised store. These aren't conventions or recommendations. Teams cannot remove or override them. The shared Terraform SQL module provides opinionated defaults that land compliant from day one, but it's the policy layer that makes compliance permanent. New services can't drift even if they try.

In 2026, with AI tools enabling everyone - engineers, analysts, and non-technical contributors - to spin up infrastructure and access production data, the blast radius of poor access hygiene has never been wider. Carlos will walk you through the full journey - from the first Terraform commit to production-enforced cloud policies - including what broke along the way, what we over-engineered the first time, and the organisational side of handing access ownership back to product teams.

You'll leave with:

  • A blueprint for self-service database access using just-in-time privilege elevation and identity provider groups

  • A clear picture of how cloud-native policy enforcement makes compliance immutable - not just recommended

  • Honest lessons from the rollout: what broke, what surprised us, and the org change management side of removing the Platform team from the critical path

  • A framework for thinking about access guardrails in the AI era - where anyone can become a data consumer, and the blast radius of poor governance has never been wider

This talk is for platform engineers, DevSecOps practitioners, and anyone who has ever found themselves as the bottleneck on access governance.

No access requests were harmed in the making of this talk.

Carlos Augusto Pega

Carlos Augusto Pega is a Senior Platform Engineer at Mews, based in Barcelona. With 15+ years of experience spanning the full software development lifecycle - from frontend and backend engineering to DevOps, platform, and security - he has built and shipped software at every layer of the stack.

Beyond engineering, Carlos co-founded a company he helped grow to 50+ people, navigating the full operational and organizational challenges of scaling a business from scratch.

Originally from Argentina, Carlos brings the same patience required for a proper asado to platform engineering - good infrastructure, like good fire, can't be rushed.

LinkedIn