Authority without the admin console.
One role-aware portal for employees, managers, application owners, AI operators and auditors. Request, use, approve, review and prove authority without exposing platform configuration.
What you can do here
Capabilities appear according to your role and ownership.
Understand what is approved and activate eligible temporary access.
Make business decisions with usage and risk context.
Trace approved, provisioned and actually exercised authority.
Attention
Items relevant to your current role.
Request awaiting approval
JIT eligible · standing access zero
Authority aligned
What you are authorized to do.
Business authority is shown separately from target access. An approved authority may remain active while standing target access remains zero.
| Authority | Application | Business owner | Target state | Runtime | Status |
|---|---|---|---|---|---|
| Finance Reporting Read & export approved reports | Finance Analytics | Finance Control | Standing | Observed | Active |
| Production Support Approved support authority | Cloud Platform | Platform Ops | Zero · JIT eligible | Inline | Activate |
| ERP Purchasing | ERP | Procurement | Not provisioned | Observed | Pending |
Request the business authority you need.
Request an application, role, business capability or bounded authority. Target entitlements are derived during fulfillment rather than being the business request itself.
New request
Describe the business need.
Purchasing operations and approved transaction scope.
Time-bound operational support authority.
Reporting and approved data export capability.
Request context
Business justification and duration travel with the grant.
Keep the authority. Remove the standing access.
Activate temporary target access from an existing certified authority and return the provisioned state to zero when the work is complete.
Production Support
Temporary role activation
remaining
Finance Share
Session-bound authority
Standing target access: zero
Cloud Deployment
Ephemeral token
Runtime decision required
Lifecycle
Decide with business and execution context.
Managers and owners approve authority, not obscure technical entitlements. Usage, conflicts and provisioning impact are shown before the decision.
| Requester | Authority | Context | Observed use | Recommendation | Action |
|---|---|---|---|---|---|
| sarah@acme.com | Production Support | Project Orion | Prior support activity | JIT suitable | |
| finance-agent-prod | ERP Purchasing | Agent owner: Finance | Bounded runtime activity | Owner review |
Review authority with evidence, not guesswork.
Recertification remains a first-class governance control. Runtime evidence and target state help owners decide whether authority should remain, change, move to JIT or be revoked.
| Subject | Authority | Provisioned | Execution | Suggested action |
|---|---|---|---|---|
| john@acme.com | Cloud Admin | Standing | No recent use | Convert to JIT |
| billing-agent | Billing API | Scoped token | Regular bounded use | Keep |
Govern authority for your applications.
Business-facing ownership view of requests, authority, target alignment and usage. Connector wiring remains in Console Pro.
ERP
Procurement · Business critical
94% aligned
11 active authorities · 2 findings
Finance Share
Finance · Restricted
JIT enabled
Standing access minimized
Sales CRM
Sales · Standard
Review due
6 authorities require certification
See the authority boundaries of non-human identities.
Operators see active grants, ownership, runtime decisions and temporary credentials without gaining platform-administrator access.
| Identity | Owner | Authority | Provisioned state | Runtime | Last decision |
|---|---|---|---|---|---|
| finance-agent-prod | Finance Automation | ERP purchasing operations | Ephemeral | Inline | Allowed |
| deploy-pipeline | Platform Engineering | Production deployment | Token on demand | Observed | Within authority |
| support-agent | Service Operations | Support tools | Scoped | Inline | Blocked |
Source of truth versus reality.
A simplified governance projection of the Watchdog engine: what was approved, what exists in the target, and what authority was actually exercised.
AUTHORITY ALIGNED
| Subject | Comparison | Finding | Owner action |
|---|---|---|---|
| john@acme.com | T2 ↔ T3 | Dormant standing access | Review JIT conversion |
| support-agent | T1 ↔ T3 | Runtime action outside authority | Review |
Trace authority from approval to execution.
Search an identity, application, authority or execution event and inspect the complete T1/T2/T3 lineage.
Evidence trace
Owner, purpose, scope, certification and policy version
Provisioning source, target entitlement and validity window
Observed action, runtime source, decision and timestamp
Aligned · no unresolved exception
Assurance
Evidence is presented read-only to audit personas.
Authority aligned
Owner certified
Target state verified
Package evidence for assurance and audit.
Create bounded evidence packages from authority, provisioning, execution, recertification and reconciliation history.
T1/T2/T3 lineage for selected identities, applications or controls.
Decision history, ownership, justification and evidence used.
Detected drift, remediation, verification and closure.