Access on Demand
No Change
trial
Access on Demand replaces standing access with audited, time-bound elevation to sensitive systems. We trial it under Technique when SSO can support the workflow.
Summary
When to use: Production or sensitive systems where compliance requires logged reason and duration for privilege elevation, and your IdP supports SAML or OIDC group workflows.
Implementation pattern: Grant standing groups plus aod_<group> variants. Provide a request UI that logs reason, issues a short-lived session token with the elevated group, and expires access on schedule. Downstream systems authorize on the non-aod group names.