DocsPeople and access

Temporary access

Ask for a role for a while, like production admin for two hours. Someone approves, and the access is removed by itself when the time is up.

Most people need powerful access only now and then: production admin during an incident, cluster admin to debug an upgrade. With temporary access, nobody keeps that access standing.

  1. Someone asks for a role, for a set time, with a reason.
  2. Someone else approves it.
  3. OpsNexa Online grants it on the platform, to the person’s own account.
  4. When the time is up, OpsNexa Online removes it.
Temporary access: a request waiting for a decision, production access running now, and the roles people can ask for.
Requests, what is active now, and the roles people can ask for.

Roles people can ask for

An admin decides what can be asked for, under Temporary access → Add role.

PlatformWhat is grantedHow it ends
AWS accountMembership of an IAM group (like production-admins), or a managed policy attached to the person’s IAM userRemoved from the group, or the policy detached
Google Cloud projectA role (like roles/editor) for the person’s Google account, with a time conditionGoogle itself stops honouring it at the end, and OpsNexa Online removes the binding
Azure subscriptionA role assignment (like Contributor) for the person’s Entra ID accountThe role assignment is deleted
Kubernetes clusterA cluster role (like cluster-admin), bound to the person’s user name (their email, as most clusters with single sign-on know them)The binding is deleted
OpsNexa OnlineThe developer or admin roleThe person gets their usual role back

Each role has:

  • a longest time, from 15 minutes to 7 days;
  • who approves it: an admin, or an admin or a lead of one of the requester’s teams. The person who asked can never approve their own request.

Ask

On Temporary access:

  1. Pick the role.
  2. Choose how long.
  3. Say why. The reason goes to whoever approves, and into the audit log.
  4. Press Ask.

Approvers get the “Someone asks for temporary access” notification. In the Slack app it comes with Approve and Turn down buttons. You can also ask from your AI assistant: “ask for Production admin for 2 hours to rotate the database password”.

While it lasts

  • Active now shows each grant and when it ends.
  • End now: the person can end it early, and so can an admin. It is removed at once.
  • When the time is up, OpsNexa Online removes it within a minute. The person is notified when it is granted, turned down, ended or expired.
  • Unanswered requests lapse after 24 hours.
  • If a platform refuses to grant, the request shows why and nothing is granted. If it refuses to remove, the request shows why and a critical “Temporary access” notification goes to the channels that follow it, so someone removes it by hand.

Every request, decision, grant and removal is in the audit log, with who, when and why: the evidence auditors ask for about privileged access.

Something unclear or missing? Tell us, or press the ? at the top of OpsNexa Online for the guide and tours inside the product.