skip to content

Break-Glass Access

A pre-authorized, time-boxed and loudly logged route to a credential nobody holds day to day, reviewed after every use. Asked because an untested one is found broken during the incident.

on this pageshow

questions

4

What makes a credential break-glass rather than an administrative account a few trusted engineers simply hold?

level: middleimportance: must knowfreq 55%

answer

  1. nobody carries it on a normal day
  2. decided in advance, not mid-incident
  3. bounded by a clock, not by intent
  4. opening it makes noise elsewhere
  5. every use ends in a review

basics

~10 s

Break-glass access is pre-authorized but held by nobody day to day: it is opened deliberately, bounded by a time box, alerts a channel the opener cannot suppress, and is reviewed after every single use.

solid answer

~40 s

A shared administrator credential that three people keep is a standing grant with a small membership list — it is held continuously, used silently, and bounded by nothing but trust. Break-glass is defined by four properties instead. Someone decided **in advance**, in writing, who may open it and what it reaches. Opening it starts a **time box**, so the elevated rights end on a clock rather than on someone remembering. Opening it **emits an alert** into a channel the opener does not control, so a second party knows within seconds. And **every use ends in a review**, with no exemption for a use that was obviously justified. Remove any one of those and you are back to an administrator account with a story attached.

code

yaml · 16 lines
yaml
grants:
  - name: payments-database-owner-daily
    grantedTo: payments-service-identity
    rights: [read]
    scope: payments/runtime
    standing: true            # held continuously, used silently

  - name: payments-database-owner-break-glass
    grantedTo: [oncall-engineer-individual-identities]
    rights: [read]
    scope: payments/emergency
    standing: false           # nobody holds this on a normal day
    maxDuration: 60m          # ends the rights, not the value read
    requiresReason: true
    alertsTo: security-channel # not writable by whoever opens it
    reviewDueWithin: 24h

go deeper

for a junior

Recall the shape: a credential nobody uses day to day, kept for emergencies, that anyone allowed may take but that makes noise when taken. Contrast it with a password a few people simply keep.

for a middle

Name all four properties and explain each mechanically: pre-authorization, a time box on the rights, an alert to an independent channel, and a review of every use. Say what the time box does not do.

for a senior

Show the operating reality: who is on the pre-authorized list and how it stays current, where the alert lands at 02:00, and what happens the morning after. Mention that the window ending leaves the read value untouched.

for a principal

Frame the trade you are making. A route that is safe to use but slow or blameful gets routed around, so the design has to buy visibility without buying delay, and the standing grants it was meant to replace have to actually be withdrawn.

## What break-glass actually names A **break-glass credential** is one that nobody holds during normal operation and that a pre-authorized person can take, on their own initiative, when the situation demands it. The name is borrowed from the alarm behind glass on a wall: the glass is not a lock and it is not there to stop you. It is there so that taking the action is *deliberate*, *visible* and *countable*. Break-glass does not make emergency access harder. It makes emergency access **loud, bounded and attributable**. That is a different object from three things it is routinely confused with. - **A standing administrative grant with few holders.** Held continuously, exercised silently, ended by nothing. Whether three people or thirty hold it changes the size of the problem, not its shape. - **Access decided by a person at the moment it is asked for.** That is a legitimate control where the decider is reachable and the request can wait. Break-glass exists precisely for the case where neither is true, which is why the decision is taken **in advance** and the compensating control moves to **after** the fact. - **A credential sealed in an envelope in a cabinet.** Custody with no time box, no alert and no review is a shared secret with ceremony attached to it. ## The four properties 1. **Pre-authorization.** Written before the incident: which identities may open the route, what the route reaches, and the circumstances that justify it. Written under no pressure, by people who can say no. 2. **A time box.** The elevated rights end on a clock. Be precise about what this buys: the time box ends the *rights*; it does not withdraw the *value* that was read during the window. A credential read at 02:16 is still a credential at 09:00 unless something replaced it. 3. **An alert on use.** Emitted at the moment of opening, carrying the identity that opened it and the stated reason, into a channel the opener does not own and cannot silence. Note that this is a signal on a **successful** action — alerting on failed authentication would never see it. 4. **A review after every use.** Including the uses everyone agrees were justified. A route whose reviews are skipped when the reason is good has no reviews, because the reason is always good. | Property | What it actually prevents | How it fails in practice | |---|---|---| | Pre-authorization | Deciding who may act while the service is down | The list names people who left, or roles nobody maps to identities | | Time box | Elevated rights that quietly become permanent | The window is generous enough that nobody notices it is still open | | Alert on use | A use only the user knows about | The alert routes to the opener, or to a channel nobody reads at 02:00 | | Post-use review | The route widening one justified use at a time | Reviews happen only for uses somebody disputed | ## Why the alert is the load-bearing property Strip the alert and the route becomes indistinguishable from what an intruder wants: a credential nobody holds, that reaches a great deal, that nobody watches, and that leaves no owner behind. The alert is what converts *access* into *an event*. It is also what makes the route safe to leave genuinely usable — you do not need to slow the route down to control it, because you can see every use of it. The alert must therefore satisfy two things that are easy to miss. It must reach somebody **other than the opener**, because a signal the subject can suppress proves nothing. And it must be understood as **observation, not accusation**: if opening the route is treated as a black mark, engineers stop opening it and quietly keep a copy of the credential instead, and you have lost both the narrow grant and the visibility. ## What this buys the rest of the estate The usual justification for a broad standing grant is the emergency nobody could otherwise handle. A route that is known to work removes that justification, which lets everyday grants be sized for everyday work. That argument is the reason break-glass is worth its cost, and it only holds if the route is rehearsed and fast enough to be believed. ## What an interviewer is listening for Not the phrase "break-glass". They want the four properties named, the distinction from a standing grant made cleanly, and one honest statement about the limits: the window ending does not undo the read, and the route is worthless if it has never been opened.

  • Why must the alert on a break-glass use reach a channel the person who opened it cannot suppress?
    Because the alert is the only control that operates while the rights are live, and a signal its own subject can mute proves nothing to anyone else. Routing it to an independent channel gives a second party the chance to ask "is that you?" within seconds, and it means an intruder who reaches the route cannot quietly hide the fact. It also fixes attribution before memories and pressure blur it.
  • How does a break-glass route differ from access a person approves at the moment it is requested?
    The decision moves in time. Approval at the moment assumes an approver is reachable and the work can wait for them; break-glass assumes neither, so the judgement is made in advance and written down. The cost of that trade is that nothing stands between the engineer and the credential during the window, which is why the alert and the mandatory review carry the weight that an approver would otherwise carry.

The alarm behind glass on a wall: the glass stops nobody, it just makes sure that taking the action is deliberate and that everyone hears it break.

saying these in an interview costs you the question

  • It is just the shared administrator password a few trusted people memorise
  • Nobody would open it without a real emergency, so alerting is unnecessary
  • Sending the alert to the engineer who opened the route is enough
  • Having a break-glass route means everyday grants can safely be broader
  • A route that has never been opened is proof that it works
open as a page

After a break-glass credential has been used during an outage, what must the post-use review produce?

level: seniorimportance: should knowfreq 34%

basics

~20 s

A post-use review must produce a record of who opened the route, when and why, which values were actually read, whether each has since been replaced, and a sign-off by somebody who did not open it.

open as a page

Your break-glass route is opened for the first time during an outage and fails - what should a rehearsal have proven about its dependencies?

level: seniorimportance: should knowfreq 42%

basics

~20 s

A rehearsal has to prove the route opens while the failing system is unavailable: the identity used to open it, the place the emergency value is held, the alert path and the operator's own access must not depend on what is down.

open as a page

Why does keeping a credible break-glass route available let an estate's everyday grants stay narrower than they otherwise would?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

Standing broad rights are usually justified by the emergency nobody could otherwise handle; a rehearsed emergency route removes that justification, letting everyday grants match everyday work - provided opening it is fast and blameless enough that nobody keeps a private copy.

open as a page