Just-in-time access

Access that expires without anybody remembering

Standing access is the risk. What replaces the admin grant from 2024 that nobody took back.

Access is granted for a window and ends on its own, without anybody remembering to end it. Say 4 hours during an incident, the life of one ticket, or a named period somebody approved.

The default becomes no access, and every exception carries a reason and an end time. That is worth stating plainly, because standing access does not exist because anybody decided it should. It exists because removing access is somebody's afternoon and leaving it is free.

So a grant you made for a migration in 2024 is still there, the person who asked for it has left, and nobody can tell you whether removing it breaks something.

What just-in-time actually changes

Not the approval. The expiry.

When you approve permanent admin access you are making a decision you will never revisit, so the honest response is caution, which in practice means delay. An approver deciding on 4 hours is making a decision that undoes itself, so they can afford to be quick.

That is the whole mechanism. Expiry does not make access safer by being clever. It makes approval cheaper by being reversible.

Three shapes

Time-boxed. A fixed window set by policy, not chosen in the moment. A window of 4 hours of production access during an incident, expiring whether or not the incident closed. Needing longer means asking again, and a second request is a signal worth having.

Task-bound. Tied to the thing it was for. Access granted against a ticket ends when the ticket closes.

Standing, and marked as such. Daily access should not require daily theatre. What changes is that it is recorded as a decision somebody made, which gives the next access review a short list of real exceptions instead of everything anyone ever asked for.

Eine Zugriffsanfrage in Slack: AWS, die Vorlage für Rufbereitschaftseskalation, eine automatisch gesetzte Dauer von zwei Tagen und ein Freitextfeld für die Begründung.

Die Anfrage dort, wo ohnehin gearbeitet wird. Dauer und IAM-Gruppen kommen aus der Vorlage, getippt wird nur die Begründung.

The duration in that request was not chosen by the person asking. It came from the access template, which is how expiry ends up consistent: decided once, calmly, rather than every time under pressure.

What still needs a person

The first pass at what each template caps at. Nobody can generate that from outside your company, and getting it roughly right beats getting it precisely wrong.

Frequently asked questions

Usually it speeds them up, because the alternative is a ticket queue. A grant carrying its own expiry gets approved faster precisely because the decision is smaller.

Break-glass issues immediately against a named policy and is reviewed afterwards. It is logged as break-glass, so it never looks like a normal approval in reporting.

No. Access somebody uses daily should be standing, and marked as a deliberate decision. The point is that standing access stops being the default everything drifts into.