skip to content

Your provider says per-engagement admin grants break its 15-minute response SLA — do you keep standing access?

level: principalimportance: should knowfreq 34%

answer

  1. the SLA covers emergencies, not all work
  2. two paths: routine approval, self-activating break-glass
  3. a hard expiry replaces the approver
  4. partial scope reduction is the real win
  5. acceptance needs an owner and a date

basics

~20 s

Usually no, because the SLA covers a small set of emergency paths, not all work. Split break-glass from routine: pre-approved self-activating emergency grants with a hard expiry meet the clock, while everything else waits for approval.

solid answer

~50 s

Treat the SLA objection as a claim about a narrow set of urgent actions, and test it. Ask what fraction of engagements are genuinely emergency response; in most books it is single-digit percent. Then design two paths: routine work goes through request-and-approve, which costs minutes and is compatible with every normal ticket; emergency work uses a pre-approved break-glass grant the provider self-activates, with a hard automatic expiry and a duty to justify it afterwards to a named owner on your side. That satisfies a fifteen-minute clock without standing top-level administration. If the provider still cannot operate it, the decision stops being technical: what does the contract let you require, what does switching cost, what scope reduction can you get now, and who on your side signs for the residual exposure with a stated amount and a review date. 'The vendor said no' is not a risk decision.

go deeper

for a junior

Be ready to notice that an SLA covers urgent work rather than every task, and that a fast emergency path can exist without leaving privilege switched on all the time.

for a middle

Explain the two-path design: request-and-approve for routine work, self-activating break-glass with a hard expiry for emergencies, and why the expiry rather than the approver is what makes it safe.

for a senior

Show that you would measure how much work is genuinely emergency before conceding, and that you can bank partial wins such as least-role scoping and carving crown jewels out of the delegation.

for a principal

Own the whole trade: contract leverage against switching cost, a stated exposure figure, tiering providers so standing rights are earned, and an acceptance signed by someone with authority and an expiry date on it.

## Read the objection before answering it *Per-engagement grants break our fifteen-minute SLA* is a real operational claim, and dismissing it makes you the security person nobody consults. It is also almost always **over-scoped**: the SLA governs emergency response, while the majority of a provider's work is scheduled, ticketed and entirely compatible with waiting three minutes for an approval. So the first move is measurement, not argument: over the last quarter, how many engagements invoked the emergency clock, and what did they actually need to do? A book where four percent of work is emergency response does not justify standing top-level privilege for the other ninety-six. ## Design that satisfies both claims Two paths, not one: **Routine path.** Elevation is requested against a piece of work, approved on the client side, scoped to the least sufficient role, and expires automatically. Latency measured in minutes, which no scheduled work notices. **Break-glass path.** A pre-approved emergency grant the provider can **self-activate without waiting for a human**, which is what actually meets a fifteen-minute clock. Its safety comes from three properties rather than from an approver: a hard automatic expiry, the narrowest role that can plausibly serve an emergency, and a duty to justify each activation afterwards to a named owner on your side. Activation is a normal, blameless act; unexplained activation is a contract conversation. That design concedes the provider's operational point in full and still leaves nobody holding privilege at rest. If the provider accepts it, the objection is resolved and there is no risk decision to make. Most of the value of this question is knowing that the apparent trade-off is frequently false. ## When the provider genuinely cannot Some providers cannot, because their tooling assumes standing entitlements across the whole book, or because their margins do not survive per-client process. Now it is a judgment under constraint, and the components are: - **What the contract permits.** Can you require it at renewal, at a price, or not at all? A right you have and do not exercise is different from a right you never bought. - **What switching costs.** Provider migration is measured in months and real money. The alternative is rarely free, and pretending otherwise damages your credibility for the next argument. - **What partial scope reduction is available today.** This is where most of the real win lives. Drop the top-level role to two scoped roles. Exclude the crown-jewel tenant, subscription or system from the delegation entirely and administer it yourself. Ask for identities partitioned per client rather than one spanning the book — that is scheduling flexibility on their side, not money, and it is the single change that most reduces your exposure to their other clients. - **What the exposure is worth.** Name it as a figure, however rough. A risk with no number cannot be traded against an SLA that has one. - **Who signs.** The person accepting this must be someone who can actually carry the consequence — the accountable executive, not the security engineer who raised it and not the provider's account manager. Self-approval by the finding's raiser is the most common failure. ## What a defensible acceptance looks like If you accept, the acceptance must carry: the specific exposure in plain words, a named owner with the authority to carry it, the compensating reductions actually implemented, and a **review date** rather than permanence. Acceptances without expiry are how a temporary concession becomes the estate's architecture. Put the same clock on the risk that you wanted on the privilege. ## Tiering, which is the answer people forget Not every provider needs the same treatment. A provider administering your directory and your production platform is not the same counterparty as one that manages printers. Tier them: standing access is a privilege that a small number of providers earn through demonstrated operating practice, and everyone else works per engagement. That converts an argument you have two hundred times into a policy you defend once, and it gives the provider something to gain rather than only something to lose. ## The failure modes to avoid out loud - **Absolutism.** *Standing administration is never acceptable* ends the conversation and gets you excluded from the next one. - **Paper for prevention.** Accepting standing access in exchange for a quarterly attestation trades a control for a document. - **Indemnity as risk reduction.** A liability clause reallocates cost after the fact; it does not shorten the privilege. Useful, but not an answer to this question. - **Leaving it undecided.** An unresolved objection defaults to standing access, permanently, with nobody's name on it. Deciding badly and writing it down beats not deciding. ## The one-line version *Meet the fifteen minutes with self-activating break-glass on a hard clock, put everything else behind approval, and if the provider still cannot, get scope reduction and per-client partitioning now, then have someone with real authority accept the remainder in writing with a date on it.*

  • How can a break-glass grant meet a 15-minute clock without a human approver?
    By moving the safety from approval to expiry and justification. The provider self-activates immediately, the grant dies on a hard timer, the role is the narrowest that can serve an emergency, and each activation must be explained afterwards to a named owner on your side. Speed comes from removing the wait; safety comes from the clock and the account owed.
  • The provider will not partition identities per client. What do you get instead?
    Scope reduction inside your own tenant, which you control unilaterally: drop the top-level role to the least sufficient ones, and carve the crown-jewel systems out of the delegation entirely so they are administered in-house. That does not fix your exposure to the provider's other clients, but it caps what a single held identity is worth in your estate.
  • Who should sign the acceptance if you keep standing access?
    Someone who can carry the consequence and who is not the person who raised the finding: the accountable business or technology executive for the affected estate. Not the security engineer, not the provider's account manager. The acceptance should state the exposure, the compensating reductions actually implemented, and a review date, so it expires rather than becoming the architecture.
  • Is there a case for keeping standing access deliberately?
    Yes, for a small number of providers whose operating practice you have actually examined and where the administered estate is low-value. Tiering is the honest form of that: standing rights are earned, not default. What is not defensible is standing top-level administration over the directory or the production platform because nobody wanted the conversation.

saying these in an interview costs you the question

  • Accepts the SLA claim without asking how much work is emergency
  • Answers with absolutism that standing access is never acceptable
  • Swaps a preventive control for a quarterly attestation
  • Treats an indemnity clause as reducing the exposure
  • Records an acceptance with no named owner or review date

context