What makes a credential break-glass rather than an administrative account a few trusted engineers simply hold?
answer
- nobody carries it on a normal day
- decided in advance, not mid-incident
- bounded by a clock, not by intent
- opening it makes noise elsewhere
- every use ends in a review
basics
~10 sBreak-glass access is pre-authorized but held by nobody day to day: it is opened deliberately, bounded by a time box, alerts a channel the opener cannot suppress, and is reviewed after every single use.
solid answer
~40 sA shared administrator credential that three people keep is a standing grant with a small membership list — it is held continuously, used silently, and bounded by nothing but trust. Break-glass is defined by four properties instead. Someone decided **in advance**, in writing, who may open it and what it reaches. Opening it starts a **time box**, so the elevated rights end on a clock rather than on someone remembering. Opening it **emits an alert** into a channel the opener does not control, so a second party knows within seconds. And **every use ends in a review**, with no exemption for a use that was obviously justified. Remove any one of those and you are back to an administrator account with a story attached.
code
yaml · 16 linesgrants:
- name: payments-database-owner-daily
grantedTo: payments-service-identity
rights: [read]
scope: payments/runtime
standing: true # held continuously, used silently
- name: payments-database-owner-break-glass
grantedTo: [oncall-engineer-individual-identities]
rights: [read]
scope: payments/emergency
standing: false # nobody holds this on a normal day
maxDuration: 60m # ends the rights, not the value read
requiresReason: true
alertsTo: security-channel # not writable by whoever opens it
reviewDueWithin: 24hgo deeper
Recall the shape: a credential nobody uses day to day, kept for emergencies, that anyone allowed may take but that makes noise when taken. Contrast it with a password a few people simply keep.
Name all four properties and explain each mechanically: pre-authorization, a time box on the rights, an alert to an independent channel, and a review of every use. Say what the time box does not do.
Show the operating reality: who is on the pre-authorized list and how it stays current, where the alert lands at 02:00, and what happens the morning after. Mention that the window ending leaves the read value untouched.
Frame the trade you are making. A route that is safe to use but slow or blameful gets routed around, so the design has to buy visibility without buying delay, and the standing grants it was meant to replace have to actually be withdrawn.
## What break-glass actually names A **break-glass credential** is one that nobody holds during normal operation and that a pre-authorized person can take, on their own initiative, when the situation demands it. The name is borrowed from the alarm behind glass on a wall: the glass is not a lock and it is not there to stop you. It is there so that taking the action is *deliberate*, *visible* and *countable*. Break-glass does not make emergency access harder. It makes emergency access **loud, bounded and attributable**. That is a different object from three things it is routinely confused with. - **A standing administrative grant with few holders.** Held continuously, exercised silently, ended by nothing. Whether three people or thirty hold it changes the size of the problem, not its shape. - **Access decided by a person at the moment it is asked for.** That is a legitimate control where the decider is reachable and the request can wait. Break-glass exists precisely for the case where neither is true, which is why the decision is taken **in advance** and the compensating control moves to **after** the fact. - **A credential sealed in an envelope in a cabinet.** Custody with no time box, no alert and no review is a shared secret with ceremony attached to it. ## The four properties 1. **Pre-authorization.** Written before the incident: which identities may open the route, what the route reaches, and the circumstances that justify it. Written under no pressure, by people who can say no. 2. **A time box.** The elevated rights end on a clock. Be precise about what this buys: the time box ends the *rights*; it does not withdraw the *value* that was read during the window. A credential read at 02:16 is still a credential at 09:00 unless something replaced it. 3. **An alert on use.** Emitted at the moment of opening, carrying the identity that opened it and the stated reason, into a channel the opener does not own and cannot silence. Note that this is a signal on a **successful** action — alerting on failed authentication would never see it. 4. **A review after every use.** Including the uses everyone agrees were justified. A route whose reviews are skipped when the reason is good has no reviews, because the reason is always good. | Property | What it actually prevents | How it fails in practice | |---|---|---| | Pre-authorization | Deciding who may act while the service is down | The list names people who left, or roles nobody maps to identities | | Time box | Elevated rights that quietly become permanent | The window is generous enough that nobody notices it is still open | | Alert on use | A use only the user knows about | The alert routes to the opener, or to a channel nobody reads at 02:00 | | Post-use review | The route widening one justified use at a time | Reviews happen only for uses somebody disputed | ## Why the alert is the load-bearing property Strip the alert and the route becomes indistinguishable from what an intruder wants: a credential nobody holds, that reaches a great deal, that nobody watches, and that leaves no owner behind. The alert is what converts *access* into *an event*. It is also what makes the route safe to leave genuinely usable — you do not need to slow the route down to control it, because you can see every use of it. The alert must therefore satisfy two things that are easy to miss. It must reach somebody **other than the opener**, because a signal the subject can suppress proves nothing. And it must be understood as **observation, not accusation**: if opening the route is treated as a black mark, engineers stop opening it and quietly keep a copy of the credential instead, and you have lost both the narrow grant and the visibility. ## What this buys the rest of the estate The usual justification for a broad standing grant is the emergency nobody could otherwise handle. A route that is known to work removes that justification, which lets everyday grants be sized for everyday work. That argument is the reason break-glass is worth its cost, and it only holds if the route is rehearsed and fast enough to be believed. ## What an interviewer is listening for Not the phrase "break-glass". They want the four properties named, the distinction from a standing grant made cleanly, and one honest statement about the limits: the window ending does not undo the read, and the route is worthless if it has never been opened.
- Why must the alert on a break-glass use reach a channel the person who opened it cannot suppress?Because the alert is the only control that operates while the rights are live, and a signal its own subject can mute proves nothing to anyone else. Routing it to an independent channel gives a second party the chance to ask "is that you?" within seconds, and it means an intruder who reaches the route cannot quietly hide the fact. It also fixes attribution before memories and pressure blur it.
- How does a break-glass route differ from access a person approves at the moment it is requested?The decision moves in time. Approval at the moment assumes an approver is reachable and the work can wait for them; break-glass assumes neither, so the judgement is made in advance and written down. The cost of that trade is that nothing stands between the engineer and the credential during the window, which is why the alert and the mandatory review carry the weight that an approver would otherwise carry.
The alarm behind glass on a wall: the glass stops nobody, it just makes sure that taking the action is deliberate and that everyone hears it break.
saying these in an interview costs you the question
- It is just the shared administrator password a few trusted people memorise
- Nobody would open it without a real emergency, so alerting is unnecessary
- Sending the alert to the engineer who opened the route is enough
- Having a break-glass route means everyday grants can safely be broader
- A route that has never been opened is proof that it works