Who can request temporary access to this target?
Inspect imported directory identities, mapped accounts, target eligibility, named approvers, request state, duration, and any required step-up before access is granted.
Capability
Keep temporary human access, agent signing, external secrets, AI governance, and automation credentials on separate reviewable paths.
Temporary-access requests
Account mapping and readiness
External secret connections
AI provider, memory, and guidance controls
Operational need
The team can operate and revoke each trust path from its owning lifecycle without conflating human access, machine execution, secrets, AI, or automation credentials.
Operating signals
What you get
Where it starts
These examples enter the product surface that owns their state. They do not all become a case, ticket, owner, or shared evidence record automatically.
Inspect imported directory identities, mapped accounts, target eligibility, named approvers, request state, duration, and any required step-up before access is granted.
Review per-agent enrollment and connection state, active signing key, rotation coverage, excluded agents, test state, and rollback availability.
Use a named, testable external secret connection and store references with the workload instead of copying resolved plaintext into ordinary configuration records.
Select and validate provider credentials and model policy, then review usage, memory, source-context health, guidance, and enabled skills independently.
Create scoped credentials, display the secret only at creation, inspect their metadata, and revoke them without changing human login or agent identity.
Use readiness, directory synchronization, discovery candidates, account mapping, target policy, approvers, and guarded remediation runs before enabling requests.
How it works
The product path below names its inputs, decisions, controls, and output without implying the same lifecycle applies to every capability.
Authenticate the operator, synchronize or import eligible identities where required, and keep human roles separate from machine credentials.
Map directory identities to managed accounts, define eligible targets and approvers, and scope automation credentials to their intended interface.
Test external secret connections, configure AI provider policy, and maintain signing keys without merging those credentials into one store.
Apply request eligibility, approver and step-up policy to temporary access; use enrolled identity and signed work for agent execution.
Review request, credential, connection, usage, memory, and key-rotation state; revoke or roll back through the owning control surface.
Product model
The diagrams show that temporary human access, machine signing, external secrets, AI policy, and automation credentials are separate principals with separate lifecycle controls.
Temporary access
A request starts from an authenticated identity, mapped account, eligible target, approver policy, duration, and readiness state, with step-up applied when configured.
Machine trust
Signed workload verification is backed by staged key rotation with coverage, test, activation, retry, exclusion, cancellation, and rollback controls.
Credential separation
External secret connections can be tested and synchronized; scoped automation credentials have their own creation, metadata, one-time secret display, and revocation path.
AI governance
Credentials and model policy sit beside usage, memory, source-context health, ingestion settings, guidance, skills, and scoped interface credentials.
What it includes
These parts participate in the workflow. The record shows what was used and why it mattered.
Just-in-time access
Eligible users request time-bounded access to configured targets through account mappings, target policy, approvers, request state, and required step-up.
Directory identities, account maps, targets, eligibility, approvers, requests, and readiness
Agent identity and signing
Agent enrollment identity and signed workload verification are backed by an explicit key lifecycle with staged coverage, activation, test, re-push, exclusion, cancellation, and rollback.
Agent identity, workload signatures, signing keys, and rotation state
External secret connections
Named connections can be created, tested, resynchronized, updated, selected as default, and removed; workloads keep secret references on their owning path.
Secret connections, references, health, and synchronization
AI provider and context policy
Provider credentials and model settings can be validated while usage, retained memory, source-context health, ingestion settings, guidance, and managed skills remain inspectable.
Provider settings, credentials, usage, memory, context health, guidance, and skills
Automation credentials
Scoped credentials can be created for operations interfaces, shown once at creation, listed by metadata, and revoked without reusing a human session or agent credential.
Personal and administrative credential lifecycle
Privileged access preparation
Readiness, directory synchronization, discovery, account mapping, target configuration, approvers, and guarded remediation runs expose setup gaps before access requests depend on them.
Readiness, discovery, mapping, target policy, and guarded remediation
Control model
Integrations, AI assistance, routines, and agents use different permissions and records. The controls below describe this capability rather than a universal approval model.
Human sessions, temporary-access requests, agent enrollment, workload signing, secret connections, AI credentials, and automation credentials remain separate security principals and records.
Temporary access is limited by identity mapping, target eligibility, approver policy, duration, readiness, and step-up requirements; a configured target alone does not grant access.
Signing-key rotation is staged and observable, with explicit activation, exclusion, retry, test, cancellation, and rollback controls.
Provider validation confirms configured credentials and connectivity; it does not certify the content of an AI answer.
Credentials can be revoked on their owning path, and secret values are not described as a general-purpose shared plaintext store.
Value over time
Identify
Authorize
Verify
Next step
Book a walkthrough and I will map this workflow to the integrations and controls you already use.