PAM Capability Design · RFP Evidence · v1.0 · June 2026

Just-in-Time
Privilege Management

Reducing the time and scope for which a user is granted privileged access - not standing admin rights.

Product ZenXPAM
Status Production capability
Prepared by Zenxsys
Zenxsys
ZenXPAMPAM
Section 1 · RFP Response

RFP Response Summary

Assessment requirement

Just-in-time privilege management, which reduces the time and scope for which a user is granted privileged access.

✓ Capability: Yes - Supported
FieldResponse
Time reduction15 min – 4 h policy caps; auto-revoke; extend/revoke lifecycle; daily/weekly limits
Scope reductionResource-targeted grants; intent-locked commands; ephemeral JIT identities
ApproachJITAccessPolicy + approval workflow + policy evaluation before grant
AuditRequest, approval, scope, grant, extend, revoke, and session events logged tenant-scoped
Suggested RFP comment (≤150 chars)ZenXPAM JIT limits privilege time (15min–4h) and scope via approval, auto-revoke, intent-locked commands, ephemeral identities, and resource-targeted grants.
Section 3 · Design Goals

Less Time · Less Scope · Auto-Revoke

Grant only the privilege needed, only for the time needed, only on the resources needed - then automatically revoke it.

GoalDesign Choice
Minimize durationJITAccessPolicy Min/Default/MaxDuration; AutoRevoke on expiry
Minimize scopeSingle resource + intent allowlist + optional ephemeral identity
No standing JIT privilegePer-request approval; deprovision on revoke/expiry
Policy before grantEvaluateJITAccessRequest in policy-service
EvidenceEnhanced monitoring, session recording option, immutable audit
Separation from standard accessStandard = certified permanent accounts; JIT = temporary elevation path
Supporting Links (RFP Portal)

Evidence References

#ReferencePath
1User access request guidedocs/guides/USER-ACCESS-REQUEST-GUIDE.md
2JIT dynamic identity operator guidedocs/guides/JIT-DYNAMIC-IDENTITY-OPERATOR-GUIDE.md
3Intent-locked sessions operator guidedocs/guides/INTENT-LOCKED-SESSIONS-OPERATOR-GUIDE.md
4Privileged sessions user guidedocs/guides/user-guide/05-privileged-sessions.md
5JIT dynamic identity implementation plandocs/implementation/JIT-DYNAMIC-IDENTITY-IMPLEMENTATION-PLAN.md
Zenxsys
ZenXPAMPAM
Sections 5–6 · Time & Scope Reduction

Duration Controls & Least-Privilege Grants

Privilege is granted only for the requested window - then automatically revoked. Scope binds to a single resource, intent-locked commands, and optional ephemeral identity.

15 minMinimum duration
60 minDefault grant
4 hoursPolicy maximum
Auto-revokeOn expiry
CooldownRequest limits
1 · RequestJustification + resource + duration
›
2 · ApproveIntent scope review · policy check
›
3 · GrantTime-bound access · optional ephemeral ID
›
4 · RevokeAuto-expire · manual revoke · deprovision
JIT Lifecycle · api/v1/access/jit

Request → Approve → Grant → Expire

Create, approve, extend, and revoke JIT grants. Workflow template enforces autoRevoke: true. Daily (5) and weekly (20) request caps with 60-minute cooldown. No standing admin rights - privilege removed automatically when the window ends.

Resource ScopeSingle Target

Grant binds to one resource - not global admin role.

  • TargetSystems / TargetResources policy
  • Platform intent templates (76 platforms)
  • RemoteApp-only option
  • Cloud ephemeral IAM for console access
  • AppLocker GPO for Windows desktop JIT
Intent LockingCommand Allowlist

Justification → AI scope → approver narrows before grant.

  • Monitor · Warn · Strict enforcement modes
  • Block out-of-scope commands live
  • Baseline templates per platform
  • Approver-approved scope is source of truth
  • Step-up MFA on deviation (Warn mode)
Ephemeral IdentityJIT Dynamic

New identity per grant - not shared admin account.

  • Windows AD · local · Linux SSH
  • Vault-minted DB users
  • Deprovision on revoke/expiry/session end
  • failClosed blocks grant if provision fails
  • Permanent catalog accounts blocked from JIT
AppLocker GPO · Cloud Ephemeral IAM · Fail-Closed Provisioning
JIT vs StandingJust-in-TimeStandard (Standing)
DurationMinutes – hours; auto-expireCertified entitlement; periodic review
ScopeSingle resource + intent commandsRole-based resource sets
IdentityEphemeral JIT user (optional)Permanent privileged account

Time Controls

  • MinDuration · DefaultDuration · MaxDuration
  • AutoRevoke · ManualRevokeAllowed
  • TimeRestrictionsJson (business hours)
  • Extend requires policy approval
  • EmergencyMaxDuration: 60 min cap

Frequency Limits & Workflow

  • MaxRequestsPerDay: 5 · MaxRequestsPerWeek: 20
  • CooldownPeriodMinutes: 60
  • jitAccessTemplate - auto-revoke on expiry
  • EvaluateJITAccessRequest before grant
  • UI: Access → JIT Access · Operations → Approvals

Privilege only when needed. JIT eliminates standing admin rights by combining time caps, resource binding, intent-scoped commands, and ephemeral identities - all audited end-to-end.

Zenxsys
ZenXPAMPAM
Sections 7–9 · Policy & API

JITAccessPolicy & APIs

Policy CategoryKey Controls
DurationMin 15m · Default 1h · Max 4h · AutoRevoke
ApprovalJustificationRequired · ApprovalWorkflowJson
IntentIntentLockingEnabled · IntentEnforcementMode
MonitoringEnhancedMonitoring · SessionRecording · RealTimeAlerting
MethodEndpointPurpose
POST/api/v1/access/jit/requestCreate JIT request
POST/api/v1/access/jit/approve/{id}Approve with scope
POST/api/v1/access/jit/revoke/{id}Early revoke
POST/api/v1/policies/engine/evaluate-jit/{id}Pre-grant evaluation

UI: Access → JIT Access · Security → Policies → JIT Access Policies · Operations → Approvals (intent scope review)

Sections 11–13 · Security & Validation

Controls & Evaluator PoC Checklist

ControlImplementation
Least privilege by timeMaxDuration + AutoRevoke enforced in workflow
Least privilege by scopeIntent locking + resource binding + ephemeral identity
Approval segregationApprover cannot self-approve (workflow rules)
Audit trailRequest → scope → grant → session → revoke chain
Compliance mappingSOC 2 · ISO 27001 · PCI-DSS privileged access time limits
Fail-closed provisioningjitDynamicIdentity.failClosed blocks grant if identity creation fails
Evaluator PoC Checklist
  • Create JITAccessPolicy with MaxDuration 60 min and AutoRevoke enabled
  • Submit JIT request for single resource with business justification
  • Approver reviews intent scope and approves narrowed command list
  • Connect via brokered session; grant expires automatically after window
  • Attempt out-of-scope command; verify block/alert in Strict mode
  • Enable JIT Dynamic Identity; confirm ephemeral user created and removed on revoke
  • Revoke active grant early; confirm session terminated and identity deprovisioned
  • Verify request, approval, grant, and revoke events in audit log
  • Confirm daily request limit blocks excess JIT requests
Version 1.0Date June 2026Author Zenxsys