JIT request and approval
Structured scope, reason, duration, approver separation, and expiry.
PRIVILEGED ACCESS
Oten Privileged Access combines device trust, approval, JIT entitlement, short-lived credentials or certificates, and session audit for SSH, databases, Kubernetes, and privileged workflows.
System role: Oten Gateway PAM + Oten Endpoint PAM Agent + Control Plane
Evaluation depends on: Requires Verified Access, resource roles, approval, credential lifecycle, and protocol-specific enforcement.
The user selects a resource and role, then provides a structured business reason.
Policy checks identity, role, device trust, risk, time, and approval requirements.
An authorized approver grants a constrained window; self-approval is blocked except under an explicit disaster policy.
Gateway brokers a short-lived credential or certificate and avoids exposing a standing secret where the protocol allows.
The session is scoped to the approved resource, role, protocol, and time window.
Entitlement ends at TTL, policy revoke, or supported active-session termination, with an enforcement result recorded.
Structured scope, reason, duration, approver separation, and expiry.
Short-lived certificate or brokered credential bound to resource and role.
Long-lived secrets remain behind a controlled service when protocol and deployment support it.
Metadata, recording, playback authorization, and protocol-specific termination behavior.
A correct user role does not override a device that fails the resource's trust requirements.
Dual authorization, command policy, or additional assurance may be required for sensitive actions.
FAQ
No. Oten should use that term only for protocols and flows that do not expose or rely on a password. A brokered upstream password is still a password even if the user never sees it.
No. Device Trust is an additional policy gate. Identity, role, resource scope, approval, and session constraints remain independently required.
Recording depends on protocol support, privacy policy, retention, deployment, and session mode. Support must be defined by protocol and enforcement mode rather than stated as a universal claim.
Next in Oten Access
Review the Gateway enforcement model and the security dependencies required for privileged workflows.