01Challenge
Server access was granted manually, passwords of technical accounts were handed to people and temporary rights were never revoked. The client needed a platform concept that brings order: who has access to what, on what basis and until when.
02Solution
- Sign-in with a corporate Active Directory account, MFA and single sign-on
- An access broker opens an SSH or RDP session on behalf of a technical account — the secret from the vault is never shown to the user
- Permissions are the intersection of role, department, server group, account type and resource policy
- Anything beyond standing rights is a time-boxed request with automatic revocation
- Every action is audited and events are forwarded to a SIEM
03Results
- A concept covering the full specification: discovery, scenarios, UI concept, architecture, access matrix, security and roadmap
- A clickable prototype of every screen with a role switcher
- Traceability to acceptance criteria; all materials open in a browser without installing anything