Reduce standing privilege

Give operators individual accounts and elevate only for the required action. Protect the identity system with strong authentication and keep the recovery account separate from daily credentials.

Record command or session evidence appropriate to the risk without capturing secrets. Shared root passwords remove attribution and complicate revocation.

  • Named account
  • Elevation reason
  • Session start and end
  • Credential rotation

Test emergency access

Store break-glass material outside the primary identity and hosting failure boundary. Access must still work during directory, network, or control-panel failure.

After use, rotate exposed credentials, review the session, reconcile changes, and close temporary network rules.

Verification checkpoint

Disable the normal identity path in a rehearsal and complete, record, and revoke an emergency session without sharing a standing password.