How it works
From request to revoke in four steps.
01
Ask
Someone asks where they already work.
A Slack command, the web inbox or the API. Clavra attaches the ticket, the device and the person’s on-call status before anyone sees the request.
Requests need a reason and, if you want, a ticket
Low-risk requests can be approved by policy
#access-requests
PR
Priya Raman · 13:58
/access prod-payments-db read-write 2h INC-4471
Clavra · request sent to Hana K.
Low risk: Priya is on call and INC-4471 is open at severity 2.
Approve 2h
Deny
Daniel Oyelaran · AdministratorAccess on halden-prod
Flagged
Why this is flagged
First sign-in from this laptop, 11 minutes ago
Not on call this week. His usual role is PowerUser
Admin can change IAM policies and read billing exports
Rotating a KMS key needs kms-rotate, not admin.
Grant kms-rotate, 1h
Deny
02
Decide
You approve, narrow or deny in one click.
Risk signals sit next to the buttons. If a smaller role fits the ticket, Clavra suggests it, and you can shorten the window before you approve.
Two approvers for admin roles, if you choose
Keyboard shortcuts: A approves, D denies
03
Grant
Access starts, with an end time attached.
Clavra adds the person to a just-in-time group or role in the target system. The expiry travels with the grant, so on AWS and Google Cloud it ends even if Clavra is offline.
No shared accounts or passwords
The permission graph updates as you decide
Permission path
Daniel O.
Just-in-time
halden-prod
kms-rotate · 1h
ends 15:02
halden / audit
14:02:12 narrowed d.oyelaran admin → kms-rotate
14:02:13 granted kms-rotate halden-prod 1h
15:02:13 expired kms-rotate on schedule
04
Expire
It ends on schedule and the log says so.
When time is up Clavra removes the grant and writes the expiry next to the approval. Auditors get one CSV instead of three weeks of screenshots.
Every line signed and chained
Export to Splunk, Datadog or S3