A developer no longer connects straight to a database: they run a tunnel script that opens an approval request in Slack through an SSM document. The tunnel only exists once the request has been approved — and every open connection is then flagged in Slack.
Generic diagram: instances, repositories, channels and modules are named by function. The architecture is shown for illustration, independently of any organisation.
The script is called twice: once to file the request, and once — after the verdict — to actually open the tunnel. In between, nothing is open.