Skip to content
Stackship documentation Svenska

Access controlUsers

Just-in-time access

Request a role for a few hours, get it approved by an owner, activate it, and let it expire.

Instead of holding a powerful role all the time, you can request it for a limited time. An owner approves the request, you activate it when you need it, and the role lasts until the time runs out. While it is active it counts exactly like a role assignment — an Owner grant made this way lets you do everything an Owner can at that scope.

Request access

  1. In the portal at https://portal.example.com, open Access control (IAM), go to JIT access and choose Request access.
  2. Request details:
    • Role to request — any built-in or custom role, except Platform Owner, Platform Contributor, Platform Reader and LLM Gateway Consumer. The list shows those four too, but a request for one is refused when you submit it: "This role cannot be granted via JIT. Use the role-assignment write path instead."
    • Scope — filled in with the boundary. Narrow it to a resource group or a resource by extending it, for example /boundaries/<boundary-id>/resourcegroups/web. It must stay inside this boundary.
    • Business justification — required, up to 1000 characters. The approver decides on it.
  3. Duration — 1, 2, 4 or 8 hours, or a custom duration in whole hours between 1 and 8.
  4. Choose Submit request.

The request is Pending. Owners at or above the scope are sent an email about it, when the platform is set up to send email. The members of a group that holds Owner are sent it too, although Owner through a group does not let them decide the request.

You request for yourself, and you must be a member of the boundary's tenant.

From a blocked action

Some pages offer a request where you lack the rights to finish what you are doing — for example giving a container instance access to a vault you do not own, or deploying a blueprint. Choose Request temporary access: the role and scope are set for you, and the justification is filled in but can be edited. The same box then shows the request's progress and an Activate access button once it is approved.

Approve or decline

An Owner or Platform Owner at or above the request's scope decides it. The deciding role must be assigned to them directly or held through an active just-in-time grant — Owner through a group is refused — and they also need rbac/members/write on the boundary whose JIT access tab they use. You cannot decide your own request.

  1. Open JIT access. Anyone who can decide sees every request, with Show all requests on.
  2. On a Pending request, choose Approve or Decline.

The requester is sent an email with the decision. A declined request cannot be reopened; the requester submits a new one.

Activate

Approval does not start the clock. When you need the access, open JIT access and choose Activate on your Approved request. The role applies from that moment for the duration you requested, and Time remaining counts down. Only the requester can activate a request.

Statuses

Status Meaning
Pending Waiting for an owner. A pending request that nobody decides expires after 48 hours
Approved Approved, not yet activated. It stays approved until it is activated or revoked
Active The role is in force until the time runs out
Expired The time ran out, or the request was never decided
Revoked Revoked before it expired: ended early, or withdrawn before it was decided or activated
Declined An owner refused it

Revoke

An Owner or Platform Owner at or above the scope can end an active grant early: choose Revoke on the JIT access tab and confirm. The grant ends at once; services that cached an earlier decision follow within a minute.

Revoking someone else's request needs the same rights as deciding it. The portal offers Revoke on active grants only; with stsh iam jit revoke <request-id> or the API, a Pending or Approved request can be revoked as well. The portal also shows Revoke on your own active grant, but the platform accepts that only if you hold rbac/members/write on the boundary.

Limits

  • The duration is at most 8 hours.
  • Platform Owner, Platform Contributor, Platform Reader and LLM Gateway Consumer cannot be requested; they are assigned permanently at the root by a Platform Owner.
  • Only a Platform Owner can request access at the root scope /, and only for a built-in role.

With the CLI

bash
stsh iam jit request \
  --set roleDefinitionId=<role-id> \
  --set scope=/boundaries/<boundary-id>/resourcegroups/web \
  --set 'justification=Investigate the failing deploy of shop' \
  --set requestedDuration=02:00:00
stsh iam jit list
stsh iam jit activate <request-id>

Approvers use stsh iam jit approve <request-id>, stsh iam jit decline <request-id> and stsh iam jit revoke <request-id>.