How it works
Approval sits on top of the access a member already holds. Two layers apply to a gated account:- Membership grants use access, the right to launch a session and connect to the account. This comes from the Admin, Operator, or Connector role on the folder or account, and it’s the record of who can ever get in. Credential access needs the Operator or Admin role specifically.
- Approval decides whether a member is cleared to use that access right now.
How an account becomes gated
Whether an account is gated comes down to the template it uses.- The Product Admin builds the templates and turns on Require Approval for the ones meant to be secure.
- The Folder Admin gates an account by onboarding it with one of those templates. The account inherits the requirement from its template.
- The Folder Admin then seats the approvers on the folder’s Approvals tab, since the template says approval is required but not who gives it.
Setting up an access gate
Prepare a secure template (Product Admin)
Onboard the account with that template (Folder Admin)
Seat approvers in the folder (Folder Admin)
Requesting and granting access
Filing a request
From the Accounts page, a member sees every account they can reach. Gated accounts show a key icon instead of the rocket (launch) button — select the key or select Request Access from the menu to start a request. To request, the member provides a reason and a duration, both fixed at submission. The account then shows Pending Approval until it clears. Once approved, the key icon switches to the rocket icon and the member can launch sessions until the grant expires.Reviewing a request
Approvers are notified by email and in the app when a request needs them. From Approval Requests, an approver sees the requests waiting on them, each showing the requester, account, folder, reason, and duration. A credential request carries a Credentials badge, so an approver can tell at a glance that approving hands over the raw password rather than opening a recorded session. They approve or reject the request. A single approval from any one of the folder’s seated approvers clears it; it doesn’t have to come from a specific person.The request lifecycle
Every request carries the reason and duration set by the requester and moves through a small set of states.Break-glass access
Break-glass access lets a named responder clear their own pending request without an approver. Every approver who was skipped is notified immediately. It grants no standing access. The responder still files a request, still gives a reason, and still gets a time-boxed grant. The only thing that changes is who signs it off.The two switches
Break-glass needs two switches on, and a different person owns each one:- The Product Admin turns on Allow Break-Glass on the template. This sets which accounts can ever be broken into.
- The Folder Admin names the break-glass users on the folder’s Approvals tab. This sets who can do it.
Setting it up
Turn on the template policy (Product Admin)
Name the responders (Folder Admin)
Breaking glass
There are two ways in, and both need a reason of at least 10 characters explaining why this can’t wait for an approver. The reason is recorded in the audit log and sent to the approvers who were skipped. If you already know nobody is available to approve, turn on Break glass in the request form before you submit. The request is raised and granted in one step, and the reason you gave doubles as the bypass reason. If you filed a request and then decided not to wait, reopen the account from the Accounts page while the request is pending. The sheet offers Break glass below the approval workflow. Either way, the grant is the one the request asked for. It expires on the same clock, a Folder Admin can revoke it the same way, and sessions on it are recorded like any other. Breaking glass on a credential request grants a credential reveal, not a session.What happens next
Every use of break-glass:- Emails every approver who was skipped, with the reason given
- Notifies them in the app
- Posts to the folder’s Slack channels, if you’ve configured notifications on the folder
- Writes a PAM Access Policy Bypassed entry to the audit log with the reason, the account, the folder, and how many approvers were skipped
- Marks the request with a Break-glass badge in the folder’s request history
Requests from AI agents
An agent requests access on the same terms as a person, but from the CLI instead of the dashboard. A request from an agent running as a machine identity shows the identity’s name in place of a requester’s email; one from an agent you started yourself is filed under your own name. When an agent reaches for a gated account, the request is filed for it automatically, and the account starts working on the agent’s next attempt after you approve.Frequently asked questions
When does the duration clock start, at filing or at approval?
When does the duration clock start, at filing or at approval?
Can an approver approve their own request?
Can an approver approve their own request?
Can an approver change the requested reason or duration?
Can an approver change the requested reason or duration?
Does an approver need use access to the account?
Does an approver need use access to the account?
Who can revoke access once it is granted?
Who can revoke access once it is granted?
Can a machine identity or an AI agent break glass?
Can a machine identity or an AI agent break glass?
Can someone break glass on another person's request?
Can someone break glass on another person's request?
Does break-glass give longer or wider access than an approval?
Does break-glass give longer or wider access than an approval?
What happens if the account moves or the folder's policy changes mid-request?
What happens if the account moves or the folder's policy changes mid-request?
Do changes to a folder's approvers apply to requests already in flight?
Do changes to a folder's approvers apply to requests already in flight?