Platform

Privileged access you can actually audit

Replace shared root accounts, jump boxes, and untracked SSH keys with identity-based, just-in-time access to servers, Kubernetes clusters, and databases — every session logged.

Terminal, Kubernetes and database behind one policy gate with session recording

Every protocol, one policy

Write the rule once — it governs SSH shells, kubectl, database sessions, and internal HTTP APIs the same way. Access follows the person: every session maps to an identity from your provider, expires on schedule, and lands in the audit log without anyone remembering to enable anything.

access sessions — live
mei@corpssh prod-db-300:42:10RECORDED
ci-deploykubectl apply00:03:22AUTO
sam@corppsql billing · read-only01:12:55RECORDED
acme:vendorssh stage-1expires 17:00SCOPED
unknownssh prod-db-3—DENIED
Humans, CI jobs, and vendors — each with their own identity and scope.

Just-in-time, not standing access

Engineers request temporary access to production when they need it; it expires automatically. Sensitive hosts can require an explicit claim before connecting, and high-risk destinations can ask for a fresh MFA prompt. Nobody holds root "just in case" anymore.

// who may SSH into tagged prod hosts
{
  "src": ["group:sre-oncall"],
  "dst": ["tag:prod:22"],
  "action": "check-in",
  "duration": "4h"
}
 
# request access from the CLI
$ openvlan access request --host prod-db-3
Approved. session expires in 4h

Sessions that record themselves

Audit evidence becomes a side effect of working, not a project. Enable check mode and every SSH session is captured as an asciinema replay your auditors can watch — searchable by person, host, and time. Database sessions get query-level logging; policy edits land in version control with the approver's name attached.

session replay — archive
#8f3a2cmei@corp · prod-db-338 min▶ REPLAY
#9b71d2ci-deploy · cluster-a3 min▶ REPLAY
#77c1e9sam@corp · billing psql72 min▶ REPLAY
#d0e4f7acme:vendor · stage-119 minEXPORT
Stream to Datadog, Splunk, or any webhook — or keep it in the console.

Least privilege, built in

Who can reach what is defined by identity, reviewed in version control, and enforced on every connection.

Just-in-time elevation

Temporary, auto-expiring access to production. Nobody holds root between incidents.

Short-lived certificates

Issued per session, never stored on disks. No standing keys to rotate by spreadsheet.

Check-in / check-out

Sensitive hosts require an explicit claim before connecting — one engineer at a time.

MFA step-up

High-risk destinations can demand a fresh prompt at connect time, not just at login.

Keystroke recording

SSH sessions captured as searchable asciinema replays. Watch what happened, when.

Query-level audit

Postgres, MySQL, and Redis sessions logged per user, down to the statements.

Policy in version control

Every ACL change reviewed in pull requests. Roll back any change, see who approved it.

SIEM export

Stream access logs to Datadog, Splunk, or any webhook endpoint your SOC already watches.

SSH

Same ssh command, identity instead of keys, Tab-completion of allowed host names.

Kubernetes

kubectl as themselves — admission, RBAC, and audit bind to identity, not emailed kubeconfigs.

Databases

Authenticating proxies broker per-user sessions for Postgres, MySQL, and MongoDB.

Anything TCP

Point any client at a local port; the mesh forwards under the caller's identity.

Questions and answers

Do we have to replace everything at once?
No. OpenVLAN access and your existing keys, bastions, or PAM tools coexist. Migrate per host, per protocol, per team — most teams start with production SSH and grow from there.
What happens to standing access during migration?
Both models apply at once: legacy keys keep working where you haven't removed them, while OpenVLAN policies govern the resources you've moved. Tighten at whatever pace your on-call rotation can absorb.
Can session recording be turned off for some teams?
Yes — check mode is per ACL rule. Record production DBAs fully, log metadata-only for staging, and skip recording entirely where policy allows.
How do vendors and contractors get access?
Scoped identities with email auth: they see exactly the hosts a policy names, sessions expire on a schedule you set, and every action lands in the audit trail like anyone else's.
Does this replace our PAM vault?
It replaces the parts teams actually feel — shared credentials, jump hosts, manual checkout. Some customers keep vaults for application-to-application secrets and use OpenVLAN for everything human.
What does an auditor actually receive?
A person, a destination, a time window, and — where enabled — a keystroke replay. Exportable as JSON, CSV, or streamed continuously to your SIEM.
How long does rollout take?
The first host is minutes: install, log in, connect. Team-wide policy takes an afternoon to draft in review, and migration from a legacy PAM typically runs a few weeks per protocol.

Kill the shared root password

Move to per-person, expiring, audited privileged access in an afternoon.