Requesting
Approving
What happens at approval time
- The user’s session receives the requested role for
duration. - A time-bounded binding is written to the audit log.
- When the window closes, the binding expires — no cleanup needed.
- Every action taken during the elevated window is annotated with the request id in the audit stream.
Access lists (standing pre-approved sets)
For scoped, standing access that avoids per-session approvals, define an access list:Related
Roles & bindings
Where
require_approval_for and thresholds live.Sessions
Elevated sessions are annotated with the request id.