Just-in-Time Privileged Access Design Prompt
Design a just-in-time, time-bound privileged access model that replaces standing admin rights with approval-gated, fully audited elevation for humans and pipelines.
- Target user
- IAM and platform security engineers reducing standing privilege
- Difficulty
- Intermediate
- Tools
- Claude, Cursor
The prompt
You are a senior identity and access engineer who eliminates standing privilege by making elevation temporary, approved, and auditable. I will provide: - Where privileged access exists today (cloud roles, kubectl admin, DB superuser, SSH) - Our identity provider and any existing PAM/JIT tooling (AWS IAM Identity Center, Entra PIM, Teleport, Vault) - Compliance requirements for approvals and audit trails Your job: 1. **Standing-privilege inventory** — map who and what holds permanent elevated access and rank by blast radius. 2. **JIT model** — design time-bound elevation: requester, approver, justification, max duration, and auto-revoke, mapped to the tooling I have. 3. **Access tiers** — separate routine read access from break-glass admin, with stricter controls (dual approval, shorter TTL) for the most powerful roles. 4. **Pipeline identities** — replace long-lived CI credentials with short-lived, scoped tokens (OIDC federation, dynamic secrets) and per-job elevation. 5. **Audit** — ensure every elevation, command session, and approval is logged immutably and reviewable. 6. **Rollout** — phase out standing roles without locking anyone out, keeping a tested break-glass path. Output as: (a) standing-privilege inventory table, (b) a JIT elevation workflow per access type, (c) approval/TTL policy by tier, (d) a phased decommission plan with break-glass. Validate the break-glass path before removing standing admin so an outage can never lock out all responders.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
IAM Role Trust Policy & Confused-Deputy Audit Prompt
Audit AWS IAM role trust policies for over-broad assume-role principals, missing external IDs, and confused-deputy gaps, and tighten them to least-privilege without breaking legitimate cross-account or service access.
-
systemd Service Sandboxing Hardening Review Prompt
Review a systemd unit and produce a hardened, least-privilege sandbox using directives like ProtectSystem, NoNewPrivileges, capability bounding, syscall filtering, and namespace isolation without breaking the service.
-
Outbound Firewall Egress Allowlist Hardening Prompt
Design a default-deny egress firewall policy from observed outbound traffic, locking down which destinations a host or workload may reach to contain data exfiltration and command-and-control without breaking required dependencies.
-
Break-Glass Privileged Access Workflow Design Prompt
Design a just-in-time, audited break-glass procedure for emergency privileged access — time-boxed elevation, approval, full session recording, and automatic revocation — so admins aren't sitting on standing root.
More DevOps Security & Hardening prompts & error guides
Browse every DevOps Security & Hardening prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.