ACTION TYPE · GRANT ACCESS
Access that is granted in seconds and reviewed in a quarter.
Role assignments, group memberships, API keys, temporary elevation. Helpdesk agents and provisioning scripts already grant access; the review that is meant to catch a bad grant usually comes long after it was used.
Who runs it today: IT helpdesk agents, provisioning scripts, identity workflows, CI service accounts.
The rules that usually govern it
- A requester cannot grant a role above their own
- Elevated access is time-boxed
- Sensitive roles need an approver who is not the requester
- Some conditions must hold at request time, such as MFA or a network range
Typical rule shapes, not a claim about any one organisation. A pilot starts from yours.
Where rules like these break
What the gate does
- 01
Checks each request against the proven policy before it executes. What fails never reaches the system.
- 02
Refuses when a window or population the rule depends on is missing or does not reconcile, instead of guessing.
- 03
Seals every decision, allow or block, so it can be re-checked without us.
