mongodb-security-and-data-access-hardening
MongoDB Security and Data Access Hardening
When to use
Invoke when establishing the security posture for a production MongoDB deployment, enforcing PII protection at the engine, restructuring roles and grants, adding client-side field-level encryption, or auditing an inherited deployment for auth/RBAC/encryption/audit gaps.
Do not use for: document modeling or migrations (use mongodb-data-model-and-migration); query/index tuning (use mongodb-indexing-and-query-optimization); replica-set topology (use mongodb-replication-and-ha-readiness); backup/restore procedure (use mongodb-backup-and-operational-readiness — this skill owns the backup-artifact key/access model it consumes); KMS / secret-store provisioning (infrastructure layer — this skill wires CSFLE to the KMS, it does not stand the KMS up).
Inputs
Required:
- An existing data model with PII-tagged fields from
mongodb-data-model-and-migrationand the collection PII classification fromdata-architecture.md. - Approved
architecture/securitydecisions on the authentication model, encryption posture, and PII classification, or explicit confirmation they are intentionally deferred.
Optional: