
Reducing the time and scope for which a user is granted privileged access - not standing admin rights.

Just-in-time privilege management, which reduces the time and scope for which a user is granted privileged access.
| Field | Response |
|---|---|
| Time reduction | 15 min – 4 h policy caps; auto-revoke; extend/revoke lifecycle; daily/weekly limits |
| Scope reduction | Resource-targeted grants; intent-locked commands; ephemeral JIT identities |
| Approach | JITAccessPolicy + approval workflow + policy evaluation before grant |
| Audit | Request, approval, scope, grant, extend, revoke, and session events logged tenant-scoped |
Grant only the privilege needed, only for the time needed, only on the resources needed - then automatically revoke it.
| Goal | Design Choice |
|---|---|
| Minimize duration | JITAccessPolicy Min/Default/MaxDuration; AutoRevoke on expiry |
| Minimize scope | Single resource + intent allowlist + optional ephemeral identity |
| No standing JIT privilege | Per-request approval; deprovision on revoke/expiry |
| Policy before grant | EvaluateJITAccessRequest in policy-service |
| Evidence | Enhanced monitoring, session recording option, immutable audit |
| Separation from standard access | Standard = certified permanent accounts; JIT = temporary elevation path |
| # | Reference | Path |
|---|---|---|
| 1 | User access request guide | docs/guides/USER-ACCESS-REQUEST-GUIDE.md |
| 2 | JIT dynamic identity operator guide | docs/guides/JIT-DYNAMIC-IDENTITY-OPERATOR-GUIDE.md |
| 3 | Intent-locked sessions operator guide | docs/guides/INTENT-LOCKED-SESSIONS-OPERATOR-GUIDE.md |
| 4 | Privileged sessions user guide | docs/guides/user-guide/05-privileged-sessions.md |
| 5 | JIT dynamic identity implementation plan | docs/implementation/JIT-DYNAMIC-IDENTITY-IMPLEMENTATION-PLAN.md |

Privilege is granted only for the requested window - then automatically revoked. Scope binds to a single resource, intent-locked commands, and optional ephemeral identity.
Create, approve, extend, and revoke JIT grants. Workflow template enforces autoRevoke: true. Daily (5) and weekly (20) request caps with 60-minute cooldown. No standing admin rights - privilege removed automatically when the window ends.
Grant binds to one resource - not global admin role.
Justification → AI scope → approver narrows before grant.
New identity per grant - not shared admin account.
| JIT vs Standing | Just-in-Time | Standard (Standing) |
|---|---|---|
| Duration | Minutes – hours; auto-expire | Certified entitlement; periodic review |
| Scope | Single resource + intent commands | Role-based resource sets |
| Identity | Ephemeral JIT user (optional) | Permanent privileged account |
Privilege only when needed. JIT eliminates standing admin rights by combining time caps, resource binding, intent-scoped commands, and ephemeral identities - all audited end-to-end.

| Policy Category | Key Controls |
|---|---|
| Duration | Min 15m · Default 1h · Max 4h · AutoRevoke |
| Approval | JustificationRequired · ApprovalWorkflowJson |
| Intent | IntentLockingEnabled · IntentEnforcementMode |
| Monitoring | EnhancedMonitoring · SessionRecording · RealTimeAlerting |
| Method | Endpoint | Purpose |
|---|---|---|
| POST | /api/v1/access/jit/request | Create JIT request |
| POST | /api/v1/access/jit/approve/{id} | Approve with scope |
| POST | /api/v1/access/jit/revoke/{id} | Early revoke |
| POST | /api/v1/policies/engine/evaluate-jit/{id} | Pre-grant evaluation |
UI: Access → JIT Access · Security → Policies → JIT Access Policies · Operations → Approvals (intent scope review)
| Control | Implementation |
|---|---|
| Least privilege by time | MaxDuration + AutoRevoke enforced in workflow |
| Least privilege by scope | Intent locking + resource binding + ephemeral identity |
| Approval segregation | Approver cannot self-approve (workflow rules) |
| Audit trail | Request → scope → grant → session → revoke chain |
| Compliance mapping | SOC 2 · ISO 27001 · PCI-DSS privileged access time limits |
| Fail-closed provisioning | jitDynamicIdentity.failClosed blocks grant if identity creation fails |