At FundApps, access to customer data follows the principle of least privilege. This has long been managed by providing a limited number of background-checked and trained staff with access using secure virtual desktops.
JIT is a new access control that allows clients to provide FundApps staff access to their environment for a set period based on the specific context (e.g., incident resolution, investigations). This feature serves as an extra layer of control in addition to our existing controls, such as using secure virtual desktops.
What are the benefits of JIT?
FundApps staff do not have default access to client data.
Access is granted and revoked by clients with the Administrator role.
Application access is restricted to predetermined time periods and designated FundApps staff members only.
Access is time-limited, automatically expiring once the predetermined period concludes.
As is currently the case, access is documented in the audit trail.
Client's Responsibility
❗If you choose to utilise JIT access and subsequently fail to grant CS access for support purposes in a timely manner, it will impede our ability to perform our duties effectively and fulfil our contractual obligations. This access is critical for us to diagnose issues, provide timely resolutions, and ensure the smooth operation of our services. Without it, our capacity to deliver the expected support and maintenance will be significantly compromised. Failure to provide JIT access may result in missed service levels or other consequential issues for which we cannot be held responsible. It is imperative that all necessary access permissions are granted promptly to ensure our ability to meet agreed-upon service standards.
How can I grant FundApps CS access?
1. Go to the Admin>User Management>Grant Access page and enable access by switching the toggle "Allow Access To FundApps Support."
2. If you want to grant access to our entire CS team, you can leave the "Who should have access?" section blank. Alternatively, you can enter the name of the person(s) you want to allow access to your environment.
3. Choose the duration for which you wish to grant access from the dropdown menu.
4. After the predetermined time expires, CS will no longer be able to log in.
5. You can choose the revoke access before the predetermined time ends by switching the toggle off.
It is important to note that:
After the predetermined time ends, CS will no longer be able to log in. However, the current session will continue until they log out or the session expires. In other words, CS will be logged out after the chosen duration + up to the inactivity timeout (default session duration is set to 120 minutes). The session duration is customisable and can be reduced.
All access is logged in the audit trail.