Privileged access with
a built-in clock.
Two distinct pillars: break-glass for when it burns — instant, pre-authorized, auto-expiring — and scheduled elevation for planned privileged work. Neither leaves standing privilege behind.
01 · Break-glass
When it burns: seconds, not approvals.
Break-glass profiles bind eligible people to the emergency entitlements of your critical systems, up front. Activation is one click from the allow-list — no approval detour at 3am — and the access expires automatically.
- Pre-authorized allow-list per profile — eligibility decided in daylight. Eligibility is a written row: this person or this group, this privileged right, for this long, until this date. A valid row is the approval — someone with no platform role at all gets a bounded session without a chain, without a request, without a task, and the audit names the row and who wrote it. Outside the row: a refusal that says which of the three limits you hit. And the eligible person can actually find the door: the product shows the elevation tab to whoever has a live row — a warehouse employee with no platform role included — and hides it from everyone else. The answer comes from the store, not from a role
- Time-bound by design: auto-expiry and revocation, tracked to the minute
- Activation flagged until a justification is filed — and recorded at critical severity on the immutable trail. The justification you owe after an emergency is an inbox item with a deadline — it turns urgent when it lapses, it does not evaporate. And the post-incident review is closed by the security team with a verdict on the record — cleared, or a violation. The words go in the justification the responder already owes: that one is free text, it is stored, and it is where the incident reference belongs. A field that cannot keep what you type into it is not offered here
- Coverage tracking: high-risk access with no governed emergency path is a flagged gap, not a blind spot — alongside high-risk self-service and profiles whose delivery mode doesn't match
Scheduled, time-boxed elevation
Privileged work with a start and an end.
For planned privileged work, elevation is requested, approved, granted at the scheduled start — and revoked automatically at the end. Combined with privileged tagging and admin-account routing, standing privilege stops accumulating.
- Request → approval → automatic grant → automatic revocation — that path is unchanged, now stamped as the decision it was: not pre-authorised. Tracked to the minute in RapidValue. Whether the elevation is also pushed to and pulled from the target system is a per-tenant setting; break-glass always provisions to the target
- Privileged entitlements route to admin accounts, never personal ones — the routing is strict, so a privileged right will not fall back onto a personal account that happens to exist
- Measured, not assumed: on-time-revoke percentage and failed revokes, with an evidence pack per session. A failed revoke is privilege left standing, and the target is zero
- Honest scope: we're no password vault or session recorder — pair with a PAM tool for that
See emergency access governed on your own data.
A 30-minute kickoff connects your HR feed and one system — working POC the same day.
Bring your HR feed plus one system you trust us to read — that is all the kickoff needs. No NDA, no second call with a sales engineer, no procurement form.