ACTION TYPE · GRANT ACCESS

Access that is granted in seconds and reviewed in a quarter.

Role assignments, group memberships, API keys, temporary elevation. Helpdesk agents and provisioning scripts already grant access; the review that is meant to catch a bad grant usually comes long after it was used.

Who runs it today: IT helpdesk agents, provisioning scripts, identity workflows, CI service accounts.

The rules that usually govern it

  • A requester cannot grant a role above their own
  • Elevated access is time-boxed
  • Sensitive roles need an approver who is not the requester
  • Some conditions must hold at request time, such as MFA or a network range

Typical rule shapes, not a claim about any one organisation. A pilot starts from yours.

Where rules like these break

  1. Grants chain.

    A role that may grant roles can hand out one that may grant more. Each step is within policy; the end state is not.

  2. Temporary adds up.

    Time-boxed grants renewed back to back are standing access, while each renewal passes on its own.

What the gate does

  1. 01

    Checks each request against the proven policy before it executes. What fails never reaches the system.

  2. 02

    Refuses when a window or population the rule depends on is missing or does not reconcile, instead of guessing.

  3. 03

    Seals every decision, allow or block, so it can be re-checked without us.

What you can check today

ON REQUEST

Sealed decision benches on access policies published verbatim by AWS and Microsoft, decided by our reading of their documented semantics. AWS’s and Azure’s own engines were not run. Shown in a call, not published.