Shared SSH keys
A key remains usable across people and resources after the original task, owner, or approval has changed.
PRIVILEGED ACCESS
Oten Privileged Access combines device trust, approval, JIT entitlement, short-lived credentials or certificates, and session audit for SSH, databases, Kubernetes, and privileged workflows.
System role: Oten Gateway PAM + Oten Endpoint PAM Agent + Control Plane
Evaluation depends on: Requires Verified Access, resource roles, approval, credential lifecycle, and protocol-specific enforcement.
A key remains usable across people and resources after the original task, owner, or approval has changed.
The decision is not durably linked to the resource, role, device, credential, session, or expiry.
A valid administrator role can still be used from a device that fails the production resource's mandatory policy.
Recording can capture sensitive data without clear notice, masking, retention, playback authorization, or export audit.
The user selects a resource and role, then provides a structured business reason.
Policy checks identity, role, device trust, risk, time, and approval requirements.
An authorized approver grants a constrained window; self-approval is blocked except under an explicit disaster policy.
Gateway brokers a short-lived credential or certificate and avoids exposing a standing secret where the protocol allows.
The session is scoped to the approved resource, role, protocol, and time window.
Entitlement ends at TTL, policy revoke, or supported active-session termination, with an enforcement result recorded.
Structured scope, reason, duration, approver separation, and expiry.
Short-lived certificate or brokered credential bound to resource and role.
Long-lived secrets remain behind a controlled service when protocol and deployment support it.
Metadata, recording, playback authorization, and protocol-specific termination behavior.
A correct user role does not override a device that fails the resource's trust requirements.
Dual authorization, command policy, or additional assurance may be required for sensitive actions.
Define certificate or credential issue, principal and host scope, agent behavior, renewal, expiry, server enforcement, session evidence, revoke, and connection termination.
Define database identity, role, credential injection, connection pooling, transaction behavior, session expiry, query evidence, revoke, and administrative ownership.
Define cluster identity, role or binding, token or certificate lifetime, namespace and verb scope, exec or port-forward behavior, revoke, and audit correlation.
Define upstream credential handling, desktop or browser session boundary, recording and masking, disconnect, idle and absolute lifetime, and recovery.
FAQ
No. Oten should use that term only for protocols and flows that do not expose or rely on a password. A brokered upstream password is still a password even if the user never sees it.
No. Device Trust is an additional policy gate. Identity, role, resource scope, approval, and session constraints remain independently required.
Recording depends on protocol support, privacy policy, retention, deployment, and session mode. Support must be defined by protocol and enforcement mode rather than stated as a universal claim.
Next in Oten Access
Review the Gateway enforcement model and the security dependencies required for privileged workflows.