Skip to main content

Just-in-time access

Temporary access with an explicit approval step

Use a date condition to give a named user temporary route access. An administrator or customer-built workflow approves and applies the policy change.

What this pattern controls

Scoped exception

Limit one identity to one required route.

Time-bound policy

Enforce an explicit start and end time.

Clear approval owner

Keep the business approval in the chosen workflow.

Time boundary

Set the approved access window in policy

Use a temporary policy exception for a contractor, on-call engineer, or break-glass operator who needs one route for a limited period.

  • Combine a user or email rule with date.before.
  • Add date.after when access must start later.
  • Remove the rule to revoke access before the end time.

Approval boundary

Choose a manual or customer-built approval flow

Pomerium provides the policy and API building blocks. The request and approval workflow is not a built-in one-click approval product.

  • An administrator can update policy directly.
  • A customer-built workflow can update Zero policy through the API.
  • The documented jit-example separates request and administrator routes.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo