Reduce standing privilege
Give operators individual accounts and elevate only for the required action. Protect the identity system with strong authentication and keep the recovery account separate from daily credentials.
Record command or session evidence appropriate to the risk without capturing secrets. Shared root passwords remove attribution and complicate revocation.
- Named account
- Elevation reason
- Session start and end
- Credential rotation
Test emergency access
Store break-glass material outside the primary identity and hosting failure boundary. Access must still work during directory, network, or control-panel failure.
After use, rotate exposed credentials, review the session, reconcile changes, and close temporary network rules.
Disable the normal identity path in a rehearsal and complete, record, and revoke an emergency session without sharing a standing password.