Tanflow IAM Suite & PAM - enterprise identity and privileged access security for the modern enterprise. Get a Demo →

18 July 2024 · Site Administrator

Reducing Standing Privileged Access with Tanflow Just-in-Time Access

Access granted for one incident is often still active a year later. This article examines Tanflow PAM Just-in-Time access - time-boxed privileged windows with approvals and automatic expiry - as the practical antidote to standing privilege.

Access has a way of outliving its reason. An engineer is granted production access for one incident; a year later it is still active, unused for months, waiting to be misused or stolen. Multiply that pattern across every team, every emergency and every vendor engagement, and the result is the standing-privilege problem: at any moment, far more people can touch critical systems than currently need to. Standing privilege is standing risk - every dormant grant is attack surface that exists purely because revocation depended on someone remembering.

The enterprise challenge: privilege accumulates, revocation does not

The asymmetry is behavioural. Granting access is urgent - work is blocked until it happens. Revoking access is urgent to no one. So grants happen in minutes and revocations happen at the next annual review, if the review catches them. Access recertification campaigns exist precisely because this asymmetry is universal, but they are a periodic cleanup of a continuously leaking system.

The security consequence is direct: an attacker who compromises any account inherits everything that account can reach, including every stale grant. The audit consequence is equally direct: reviewers asked to certify hundreds of standing entitlements they barely recognise tend to approve them wholesale, which defeats the review.

Why standing access became the default

Standing access is the default because temporary access was historically expensive to operate. Granting for a window meant a ticket to grant and a ticket to revoke, with the revocation ticket forgotten. Under that cost structure, permanent grants were the rational shortcut. Changing the behaviour requires changing the cost structure - expiry has to be automatic, not administered.

The Tanflow approach: privilege that expires by itself

Tanflow PAM implements Just-in-Time access as time-boxed privileged windows that expire automatically. Access is requested for a purpose and a duration, approved through the platform, exists for exactly that window, and then self-destructs. No revocation ticket, no cleanup dependency, no dormant grant left behind.

Tanflow describes three recurring patterns this supports:

  • Change-window access: a DBA team holds production database access every Saturday from 22:00 to 02:00. Outside the window, the access simply does not exist to be attacked or misused.
  • Incident JIT elevation: an on-call engineer requests emergency root for one hour; the approval reaches the approver's phone; access ends at minute sixty regardless of anyone's memory.
  • Vendor time-boxing: a hardware vendor receives RDP to one jump target for Tuesday's maintenance - recorded throughout, and gone by Wednesday.

JIT access composes with the rest of the PAM chain. The requester authenticates with MFA, Tanflow's change management workflow captures the request, its reason and its approval, credentials are injected from the vault so nothing persistent is handed over, the session is recorded, and command control polices what is done inside the window. What expires is not just a permission entry - it is the entire ability to connect.

The JIT workflow end to end

  1. An engineer requests access to a specific target, for a stated reason, for a defined window.
  2. An approver reviews and approves; the decision and justification are logged.
  3. During the window, the engineer connects through the gateway as normal - vaulted credentials, full recording, command policy.
  4. At expiry, access ends automatically. The audit trail holds the request, approval, session recording and command log as one coherent story.

Enterprise scenario

Consider an e-commerce operation whose production infrastructure was historically reachable by the whole engineering group, permanently - a legacy of growth. Moving deploy-related access to JIT windows changes the standing exposure from dozens of always-on privileged accounts to zero, with access materialising only around approved changes and incidents. When the next access review runs, the certification question is no longer "do these forty standing grants still make sense" but "were these requested windows appropriate" - a question the recorded reasons and approvals largely answer themselves.

Security and audit implications

JIT directly operationalises least privilege in its time dimension: not only the minimum access, but the minimum duration. It shrinks the window in which a compromised credential is useful, eliminates the orphaned-grant class of findings, and produces intrinsically better evidence - every access exists inside a requested, approved, recorded envelope. These are the properties assessors look for across the regulatory frameworks Tanflow maps its controls against.

Conclusion

Standing privilege persists because revocation ran on human memory. Tanflow PAM's Just-in-Time access removes that dependency: privileged windows are approved into existence and expire on their own, leaving behind not stale grants but complete audit records. The most secure privileged access is the kind that, most of the time, does not exist.

← All posts

See the platform behind the posts

Tanflow IAM Suite and PAM - on your infrastructure, live in 2-4 weeks.