Skip to main content

Just-in-Time Access Management

Configure Just-in-Time access to automatically provision and revoke user entitlements.

R
Written by Riya Sebastian
Updated over 2 weeks ago

Granting permanent access to every application an employee touches is a security risk your team shouldn't have to carry. Just-in-Time (JIT) access lets you define exactly how long a user can hold an entitlement β€” and automatically revokes it when that window closes. No manual deprovisioning. No forgotten access hanging around after a project ends.

How it works

When creating an access policy, you can now set a maximum access duration for any entitlement. Once a request is approved through your normal workflow, Atomicwork's IT agent provisions the entitlement, records the expiry timestamp, and deprovisions the access once the window closes.

Configuring JIT access

  1. Navigate to the Duration step when creating or editing an access policy, and select Just-in-time.

  2. Set your desired duration presets (e.g., 6 hours, 1 day) and toggle Allow access extension requests from expiry notifications if you want users to be able to request more time. The minimum duration is 6 hours (industry standard).

  3. Edit individual presets to configure exactly when the expiry notification should be sent before revocation.

Requesting and extending access

If extensions are enabled, they will receive an expiry notification with a button to request an extension before their access is revoked.

Monitoring access grants

You can also monitor and manage all active and inactive grants from the Access grants dashboard. Navigate to Settings > Access Management > Access Grants to view a full list of grants.

You can use filters to narrow down the list by Application, User, Entitlement, Status, or Expiry date. For example, you can filter to see all grants for a specific application like JumpCloud or grants for a specific user.

The dashboard also displays an Expiry date column, allowing you to easily track when JIT access will be automatically revoked. If you need to remove access before the JIT window closes, you can manually revoke it at any time from this page.

Clicking on any grant opens the Grant details panel, showing a complete timeline of when access was provisioned and deprovisioned.

Did this answer your question?