The first thing you’ll get push back from customer’s when doing a BYOC deployment is your permissions.
Sure, you need permissions for setting up your app (pushing updates, and when things go wrong debugging.)
However, if you go in with one role and can’t justify all permissions and how they will be used, your customer will say no.
We recommend splitting into three modes:
1. setup / teardown - more broad pemrissions to setup the app. Can be removed after a setup window or call
2. Maintenance - the minimal amount of permissions you need to push updates and manage service of your product
3. Break Glass - for all the other things. Toggle’able permissions, your customer can enable when a migration is needed or mid-outage.