skip to content

A standing right to read a customer-data credential becomes a grant issued on approval and expiring on its own — what changes?

level: middleimportance: must knowfreq 56%

answer

  1. absent by default
  2. a reason attached to every read
  3. exposure is a window, not a state
  4. approver and end time on the grant
  5. the released copy is still out

basics

~20 s

A just-in-time grant replaces an always-live right with one that exists only inside an approved window, so every read carries a reason, an approver and an end time, and nothing is left for anyone to revoke.

solid answer

~50 s

With a standing right the engineer can read the credential at any moment and nobody is asked why: the access record shows a read but no intent, and the usual way to shrink exposure is to take the right away from someone who needs it occasionally. A just-in-time grant inverts the default — the right is absent, a request names the scope and the reason, a second party agrees, and the grant carries its own end time. Three things are gained: exposure becomes a bounded window instead of a permanent state, each read is attributable to a stated reason and an approver, and a right that is never exercised costs nothing. One thing is not gained. Once the value has been released it is out; the expiry ends the right to ask again, and reaches nothing already read.

go deeper

for a junior

Recall the default being inverted: with a standing right the access is always there; with a just-in-time grant it does not exist until somebody asks and somebody else agrees, and it ends by itself.

for a middle

Explain the three gains mechanically — a bounded window instead of a permanent state, a stated reason and an approver attached to each read, and a right that ends without a cleanup task — and name what is untouched once the value is displayed.

for a senior

Show you would check that the standing right was actually removed, and that you can say which reads belong behind the gate and which would simply fail at two in the morning waiting for a person.

for a principal

Frame it as trading availability in the request path for a smaller exposure window, and say where in the estate that trade is worth making and what the unattended paths get instead.

## The two shapes of one right A **standing grant** is a rule that is always in force: an identity appears in a rule that permits reading a credential, and from the moment the rule is written until somebody edits it, that identity can read the value. Nothing has to happen first and nothing expires. A **just-in-time grant** expresses the same right as an event. By default the identity may read nothing. When it needs the value it asks — naming what it wants, why, and for how long — a second party agrees, a grant is created with an end time, the read becomes possible, and when the end time passes the right is gone again without anyone doing anything. Take the case interviewers usually reach for. A support engineer occasionally needs the credential that decrypts customer records, in order to reproduce one reported fault. Under the standing rule that engineer can decrypt customer records at three in the morning on a Sunday with no work item open, and nothing in the access record distinguishes that read from routine work: the rule permitted it, so it happened. Under the just-in-time shape the same work needs a request naming the piece of work, an approval from somebody who is not the requester, and it stops being possible forty-five minutes later. ## What actually changes | property | standing grant | just-in-time grant | |---|---|---| | when the right exists | continuously, until edited | only inside an approved window | | why a given read happened | recorded nowhere | stated in the request, stored with it | | who else knew at the time | nobody | the approver, at the moment it mattered | | how it ends | a rule change somebody must remember | the end time ends it | | cost of a rarely used right | full exposure every day | none, because no grant exists | Three gains, stated precisely: 1. **Exposure stops being a state and becomes a window.** The question *who could have read this value last Tuesday* has a short enumerable answer — whoever held an approved grant that day — rather than *everyone the rule names, all day, every day*. 2. **Every read carries intent.** The access record already says who read what and when. The grant supplies the missing column, `reason`, plus a second name that accepted that reason. That is the difference between a trail you can read and a trail you can question. 3. **The right removes itself.** Standing rights accumulate because removing one is a task somebody has to remember at a moment when nothing is broken. An expiring grant makes *continuation*, not removal, the thing that requires an action. ## What it does not change - **Release is irreversible.** The moment the value is displayed it exists outside the store — in a terminal history, a clipboard, a screenshot, a person's memory. The grant's expiry ends the right to ask again; it reaches nothing already read. If the released value is a static shared one, an approved read is still a reason to consider replacing it afterwards. - **It is not a substitute for scope.** A just-in-time grant over everything is still a grant over everything, for forty-five minutes. Scope and duration are independent dials, and the narrow scope is usually the more valuable of the two. - **It does not make the stated reason true.** It records that a reason was given and that a second person accepted it. Its strength is the cost of writing a false reason down under your own name, not verification. - **It says nothing about how long a credential released under it stays usable.** That clock belongs to the credential, not to the grant, and the two can disagree: an expired grant does not by itself stop a credential issued during the window from working. ## Where this shape stops An emergency route that nobody holds day to day — one that needs no approver precisely because the approvers may be the unreachable people — is a different mechanism with its own alarm and its own review. So is the question of how long an issued credential remains valid and how it is extended. Both are adjacent to this design, and collapsing either into it is the common confusion. ## What an interviewer is listening for That you can name the **default this design inverts**: absent unless granted, rather than present unless removed. And that you volunteer the bill without being asked — somebody has to be awake to approve, so work that cannot wait for a person should not sit behind a person. A candidate who claims just-in-time access makes the credential safer *after* it has been read has misplaced the control. A candidate who says the whole point is bookkeeping has missed that the window itself, not the paperwork, is what shrinks.

  • A team adds the approval flow but never removes the standing rights it was meant to replace. What has been achieved?
    Paperwork. The right is still continuously available, so nobody has to use the request path to read the value, and the access record still cannot distinguish an approved read from any other. The window only exists if the unconditional route is gone; until then the flow measures good citizenship, not exposure.
  • What does the access record look like afterwards that it did not before?
    Each read joins to a request: a stated reason, the referenced work, the approver's identity, the scope asked for and the window granted. A read with no matching request becomes visible as an anomaly rather than blending into permitted traffic, which is what makes after-the-fact review cheap enough to actually do.
  • Is a just-in-time grant useful when the reader is a service rather than a person?
    Rarely, and it is the main way this control is misapplied. An unattended consumer cannot wait for an approver, so the gate turns an exposure risk into a failed job at an hour nobody is watching. Machine paths are bounded by narrow scope and per-consumer credentials instead.

A standing grant is a key that stays on someone's ring; a just-in-time grant is a door a colleague buzzes open for a stated reason, which latches again by itself. What you carried out through the door stays out.

saying these in an interview costs you the question

  • Says a just-in-time grant protects the value after it has been read
  • Thinks the gain is convenience or tidiness rather than a bounded window
  • Assumes somebody must remove the grant by hand when the work finishes
  • Treats a standing read-only right as harmless because it cannot write
  • Claims approval records who read the value, which the trail already does
  • Believes a short window makes a wide scope acceptable