Break-glass emergency connections
What this page covers
Section titled “What this page covers”Something breaks at two in the morning, the asset that needs approval will not let you in, and the approver will not wake up. There has to be a way through. Break-glass lets someone who already holds connection authorization go in and deal with it, with an approver reviewing afterwards and a highlighted trail all the way. The path ships off, so an administrator opens it before anyone can use it.
What you need
Section titled “What you need”- The user already holds a standing connection authorization for that asset, inside its window. Authorization obtained from a temporary ticket does not qualify.
- At least one person eligible to review afterwards. The person who broke the glass cannot review themselves.
How to set it up
Section titled “How to set it up”Administrator: open the path
Section titled “Administrator: open the path”Go to the emergency connection section of the Access Control page:
| Policy | Shipped value |
|---|---|
| Break-glass emergency connections | Off |
| Break-glass ticket window (minutes) | 60 |
| Deadline for the after-the-fact review (hours) | 24 |
The policy decides the ticket window, and a duration passed in at the time of the request is ignored.
User: start one
Section titled “User: start one”Open the request dialog on the asset row. Below it there is a secondary entrance, “Emergency connection (when the review cannot wait)”, whose subtext explains that the connection is made immediately, an approver reviews it afterwards, and a record is kept throughout. Once you enter it:
- A confirmation dialog states which asset the emergency connection is for and what follows from it.
- Fill in the reason. It is required, and both the approver and the audit record see it.
- Press “Confirm emergency connection”, and the connection is established at once.
While the path is closed the entrance does not appear, and calling the interface directly is refused. When the asset already has a valid break-glass ticket, the system reports the existing ticket rather than issuing another.
Approver: review afterwards
Section titled “Approver: review afterwards”Go to the “Pending review” tab of the Approval Center, which carries a count of the outstanding items. Press Review, choose a conclusion (justified, or in breach), add a note if you want, and submit. The person who started the break-glass does not see their own entry and cannot review it.
Pending post-reviews can be selected together for a batch Confirm valid action, with a result for each record. A violation decision is still made individually. The initiator’s own records are excluded from the batch.
What auditors can see
Section titled “What auditors can see”- Every break-glass carries its own marker, distinct from an ordinary approval and from an administrator exemption.
- The record holds the person, the asset, the reason, and the ticket window.
- The review action records the reviewer, the time, the conclusion, and the note.
- A break-glass sends an event to the notification channels that are set up; an overdue review sends a separate reminder, repeated until the review is done.
- Every connection made during the break-glass ticket keeps the recording and command records of an ordinary connection.