
Managing and brokering privileged access to authorized human users and authorized machines on a temporary basis.

Managing and brokering privileged access to authorized human users (e.g., system administrators, operators and help desk staff) and authorized machines (e.g., systems, applications, workloads etc.) on a temporary basis.
| Field | Response |
|---|---|
| Coverage | Human operators and machine/workload identities via JIT, standard, and emergency paths |
| Approach | Request → approve → broker (Zenx Gateway) → monitor → auto-revoke with vault injection |
| Audit | Request, grant, session, command, and revocation events logged tenant-scoped |
Every path enforces time bounds, brokered connections, and revocation - eliminating standing privileged sessions without governance.
| Goal | Design Choice |
|---|---|
| Temporary by default | JIT max/default/min duration; auto-revoke on timeout |
| Human authorization | RBAC personas + approval + MFA + policy scope |
| Machine authorization | NHI registry · workload OAuth · REST vault API |
| Session brokering | tunneling-service + Zenx Gateway; no password handoff |
| Ephemeral identities | JIT Dynamic Identity - provision on grant, deprovision on revoke |
| # | Reference | Path |
|---|---|---|
| 1 | Privileged sessions (user guide) | docs/guides/user-guide/05-privileged-sessions.md |
| 2 | Session access guide | docs/guides/SESSION-ACCESS-USER-GUIDE.md |
| 3 | JIT dynamic identity | docs/guides/JIT-DYNAMIC-IDENTITY-OPERATOR-GUIDE.md |
| 4 | Access request guide | docs/guides/USER-ACCESS-REQUEST-GUIDE.md |
| 5 | RBAC & centralized policy | docs/implementation/PAM-RBAC-CENTRALIZED-POLICY-DESIGN.md |

Privileged access is brokered only to authorized human users and machine identities - never as standing shared passwords on endpoints.
Standing access with periodic certification and least-privilege review.
On-demand elevation with justification, approval, and mandatory expiry.
Expedited incident access with enhanced monitoring and post-review.
Approved grant → launch session → vault retrieve (service auth) → Zenx Gateway inject → target connect. Password never shown in user UI during normal flows.
| Component | Role |
|---|---|
| access-service | Grants, expiry, revocation, JIT identity orchestration |
| tunneling-service | Tunnel lifecycle, protocol injection, thick-client proxy |
| Zenx Gateway | Unified in-browser RDP, SSH, VNC, browser sessions |
| vault-service | Credential retrieve at connect - 6 app login resolvers |
Temporary by design. Every path enforces time bounds, brokered connections, and revocation - eliminating standing privileged sessions without governance.

| Task | Navigation | Permission |
|---|---|---|
| Request JIT access | Access → JIT Access | access.create |
| Request standard access | Access Requests | access.request |
| Approve temporary grant | Approvals inbox | access.approve |
| Connect (brokered) | My Access → Connect | Active grant required |
| Active sessions | Operations → Sessions | sessions.read |
| Workload vault API | REST / integration | vault.read (machine) |
| Method | Endpoint | Purpose |
|---|---|---|
| POST | /api/v1/access/requests | Submit access request |
| POST | /api/v1/access/requests/{id}/approve | Approve time-bound grant |
| POST | /api/v1/tunneling/sessions | Start brokered session |
| POST | /api/v1/access/grants/{id}/revoke | Revoke temporary access |
| GET | /api/v1/access/jit-identity/settings | JIT dynamic identity config |
| JIT Setting | Default |
|---|---|
| MaxDuration | 240 minutes (configurable per policy) |
| DefaultDuration | 60 minutes |
| MinDuration | 15 minutes |
| ApprovalRequired | true · JustificationRequired: true |
| Control | Implementation |
|---|---|
| Authorized users only | RBAC + policy principal matchers |
| Authorized machines only | NHI registry + resource/account linkage |
| Temporary basis | JIT duration caps; auto-revoke; no indefinite standing JIT |
| Brokered connect | Zenx Gateway + vault inject; user never sees target password |
| Compliance | SOC 2 · ISO 27001 · PCI-DSS · HIPAA session evidence |