Replace shared root accounts, jump boxes, and untracked SSH keys with identity-based, just-in-time access to servers, Kubernetes clusters, and databases — every session logged.
Write the rule once — it governs SSH shells, kubectl, database sessions, and internal HTTP APIs the same way. Access follows the person: every session maps to an identity from your provider, expires on schedule, and lands in the audit log without anyone remembering to enable anything.
Engineers request temporary access to production when they need it; it expires automatically. Sensitive hosts can require an explicit claim before connecting, and high-risk destinations can ask for a fresh MFA prompt. Nobody holds root "just in case" anymore.
Audit evidence becomes a side effect of working, not a project. Enable check mode and every SSH session is captured as an asciinema replay your auditors can watch — searchable by person, host, and time. Database sessions get query-level logging; policy edits land in version control with the approver's name attached.
Who can reach what is defined by identity, reviewed in version control, and enforced on every connection.
Temporary, auto-expiring access to production. Nobody holds root between incidents.
Issued per session, never stored on disks. No standing keys to rotate by spreadsheet.
Sensitive hosts require an explicit claim before connecting — one engineer at a time.
High-risk destinations can demand a fresh prompt at connect time, not just at login.
SSH sessions captured as searchable asciinema replays. Watch what happened, when.
Postgres, MySQL, and Redis sessions logged per user, down to the statements.
Every ACL change reviewed in pull requests. Roll back any change, see who approved it.
Stream access logs to Datadog, Splunk, or any webhook endpoint your SOC already watches.
Same ssh command, identity instead of keys, Tab-completion of allowed host names.
kubectl as themselves — admission, RBAC, and audit bind to identity, not emailed kubeconfigs.
Authenticating proxies broker per-user sessions for Postgres, MySQL, and MongoDB.
Point any client at a local port; the mesh forwards under the caller's identity.
Move to per-person, expiring, audited privileged access in an afternoon.