Glossary
Break-glass access
Also called: emergency access, firecall access
Break-glass access is a deliberate, time-boxed grant of permissions a user does not normally hold, for genuine emergencies. It exists as an explicit control because the alternative is an administrator quietly widening their own access, which is far harder to detect.
Break-glass access explained
Why pretending it is unnecessary makes things worse
There are genuine situations where someone needs access they do not normally hold: an investigation, a live incident, an incapacitated document owner, a regulator's deadline. A system with no mechanism for this produces the worse outcome — an administrator grants themselves permissions through the normal tooling, nobody notices, and the access is indistinguishable from routine.
Making the exception explicit is what makes it visible.
What makes a grant defensible
Time-boxed. It expires automatically rather than depending on someone remembering to revoke.
Alerted. Use raises a notification to someone other than the person using it — ideally the document owner and a security contact.
Logged as its own event type. Not blended into ordinary access entries, so a review can distinguish emergency access from routine access without reading everything.
Reason recorded. A free-text justification captured at the time, when the reason is known, rather than reconstructed afterwards.
Reviewing it
Every use should be reviewed after the fact. Break-glass access that is used routinely is not emergency access — it is a permission model that does not fit the work, and the review is what surfaces that.
Distinguishing it from a permission change
A permanent permission grant made during an incident is the thing this control exists to avoid: it survives the emergency, and nobody revisits it. A time-boxed grant expires on its own, which is why the time limit is the most important of the four properties above.
FAQ
Break-glass access: common questions
Should break-glass access be available to all administrators?
No. Restrict it to named individuals, and make the grant itself require a second person's approval where the estate is sensitive enough to justify the friction.
How is this different from an administrator override?
An override is a capability. Break-glass is a controlled process around a capability: time-boxed, alerted, logged distinctly and reviewed. The technical access may be identical; the accountability is not.
Related terms
- Access reviewAn access review is a periodic check that the people who have access to something still need it.
- API keyAn API key authenticates a program rather than a person.
- Data residencyData residency is the commitment that data is stored and processed within a specified country or region.
- Encryption at restEncryption at rest protects stored data by encrypting it on disk, so that physical access to the storage medium does not yield readable content.
- Permission inheritancePermission inheritance means a document takes its access rights from the folder containing it, rather than being permissioned individually.
- Role-based access controlRole-based access control grants permissions to roles rather than to individuals, and assigns people to roles.
آخر مراجعة: 28 أغسطس 2026. Browse the full glossary.