Skip to main content

Just-In-Time Access Management

Overview

We follow the principle of least privilege for access to customer data. We have long managed this by providing a limited number of background-checked and trained staff with access using secure virtual desktops.
​

Just-In-Time (JIT) is an access control that allows you to provide our staff with access to your environment for a set period based on specific contexts, such as incident resolution or investigations. This feature serves as an extra layer of control alongside our existing security measures.

Benefits of JIT Access

  1. Our staff do not have default access to client data.

  1. Clients with the Administrator role grant and revoke access.

  2. Application access is restricted to predetermined time periods and designated staff members only.

  3. Access is time-limited and automatically expires once the predetermined period concludes.

  4. We document all access in the audit trail.

Client Responsibility

❗If you choose to use JIT access, you must grant Client Success (CS) access for support purposes in a timely manner. Delaying access impedes our ability to perform duties effectively and fulfill our contractual obligations. Access is critical for us to diagnose issues, provide timely resolutions, and ensure smooth operations.

Failing to provide JIT access may result in missed service levels or other issues for which we cannot be held responsible. You must grant all necessary access permissions promptly to ensure we meet agreed service standards.

Granting Access

  1. Go to Admin and settings > User Management > Grant Access.

  2. Switch the toggle to Allow Access To Support to enable access.

  3. Specify who should have access:

    • To grant access to our entire CS team, leave the Who should have access? section blank.

    • To grant access to specific individuals, enter the name of each person you want to allow into your environment.

  4. Select the access duration from the drop-down menu.

You can revoke access before the predetermined time ends by switching the toggle off.
​

Additional Notes

  1. After the predetermined time ends, CS can no longer log in. However, an active session continues until the user logs out or the session expires. CS will be logged out after the chosen duration plus the inactivity timeout (the default session duration is set to 120 minutes, which you can reduce).

  2. We log all access in the audit trail.

Did this answer your question?