Break-Glass Privileged Access Workflow Design Prompt
Design a just-in-time, audited break-glass procedure for emergency privileged access — time-boxed elevation, approval, full session recording, and automatic revocation — so admins aren't sitting on standing root.
- Target user
- Security and platform engineers eliminating standing privileged access
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are an access-governance engineer who has replaced standing admin credentials with just-in-time, fully audited privileged access across cloud and infrastructure. I will provide: - Where privileged access is needed (cloud consoles, prod DBs, k8s admin, SSH to hosts) - Current model (standing roles, shared root, ad-hoc sudo) and pain points - Identity provider + tooling available (IdP, SSO, Vault, Teleport, cloud PIM/IAM) - Compliance requirements (approval, recording, retention) Your job: 1. **Eliminate standing privilege** — inventory current always-on admin grants and reframe to zero standing access: privilege is requested, granted briefly, then auto-revoked. Quantify the blast-radius reduction. 2. **JIT elevation flow** — design the request → approval → grant → expiry lifecycle. Specify who approves (peer vs manager vs on-call lead), max TTL, and auto-revocation. Require a stated reason/ticket per request. 3. **True break-glass path** — a separate emergency path for when normal approval is unavailable (IdP outage, P1). Define how it's triggered, who's notified in real time, the tighter audit it carries, and mandatory post-incident review. Stress it must be loud and rare. 4. **Strong auth at elevation** — require phishing-resistant MFA (WebAuthn/FIDO2) at the moment of elevation, not just login. Reject SMS/TOTP for break-glass. 5. **Session accountability** — full session recording (SSH/DB/console), command logging, and tamper-evident, append-only storage off the accessed system. No shared accounts — every action maps to a human. 6. **Scoping** — grant the narrowest role/namespace/database for the task, not blanket admin. Show how to template common elevation scopes. 7. **Detection & review** — alert on every break-glass use, periodic access reviews, and automated detection of elevations that bypass the workflow. Output: (a) the JIT + break-glass flow as a sequence, (b) approval/TTL/scope policy matrix, (c) MFA + recording requirements, (d) alerting + audit-review checklist, (e) a migration plan off standing access with rollback. Bias toward: zero standing privilege, narrow scopes, phishing-resistant MFA at elevation, and break-glass being loud, rare, and reviewed.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
S3 Bucket Policy Condition Hardening Review Prompt
Review S3 bucket and access-point policies for over-broad principals, missing TLS/encryption conditions, and confused-deputy exposure
-
Database Security Hardening Review Prompt
Audit and harden a production database (PostgreSQL/MySQL/MongoDB) — authentication, network exposure, encryption, least-privilege grants, and audit logging — without breaking applications.
-
Kubernetes RBAC Least-Privilege Review Prompt
Audit Kubernetes RBAC — Roles, ClusterRoles, bindings, and ServiceAccounts — to find overly broad grants, dangerous verbs, and privilege-escalation paths, then tighten to least privilege.
-
Audit & Logging Policy Design Prompt
Design a defensible audit-logging policy — what security events to capture, tamper-resistant retention, and high-value detection signals — so you can answer 'who did what, when' during an incident.
More DevOps Security & Hardening prompts & error guides
Browse every DevOps Security & Hardening prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.