Ir para o conteúdo principal
DocumentMS

Glossary

Break-glass access

Also called: emergency access, firecall access

Break-glass access is a deliberate, time-boxed grant of permissions a user does not normally hold, for genuine emergencies. It exists as an explicit control because the alternative is an administrator quietly widening their own access, which is far harder to detect.

Break-glass access explained

Why pretending it is unnecessary makes things worse

There are genuine situations where someone needs access they do not normally hold: an investigation, a live incident, an incapacitated document owner, a regulator's deadline. A system with no mechanism for this produces the worse outcome — an administrator grants themselves permissions through the normal tooling, nobody notices, and the access is indistinguishable from routine.

Making the exception explicit is what makes it visible.

What makes a grant defensible

Time-boxed. It expires automatically rather than depending on someone remembering to revoke.

Alerted. Use raises a notification to someone other than the person using it — ideally the document owner and a security contact.

Logged as its own event type. Not blended into ordinary access entries, so a review can distinguish emergency access from routine access without reading everything.

Reason recorded. A free-text justification captured at the time, when the reason is known, rather than reconstructed afterwards.

Reviewing it

Every use should be reviewed after the fact. Break-glass access that is used routinely is not emergency access — it is a permission model that does not fit the work, and the review is what surfaces that.

Distinguishing it from a permission change

A permanent permission grant made during an incident is the thing this control exists to avoid: it survives the emergency, and nobody revisits it. A time-boxed grant expires on its own, which is why the time limit is the most important of the four properties above.

FAQ

Break-glass access: common questions

Should break-glass access be available to all administrators?

No. Restrict it to named individuals, and make the grant itself require a second person's approval where the estate is sensitive enough to justify the friction.

How is this different from an administrator override?

An override is a capability. Break-glass is a controlled process around a capability: time-boxed, alerted, logged distinctly and reviewed. The technical access may be identical; the accountability is not.

Uma sessão de 30 minutos com um engenheiro de soluções, sobre uma estrutura de pastas e uma cadeia de aprovação parecidas com as suas — não um ambiente de demonstração genérico.