Ekyam adheres to a Zero-Standing-Access principle, a policy which prohibits persistent or “standing” access to production environments.
We also have a Just-in-Time (JIT) “Break-Glass” Protocol, where different access is provided to different users like:
→ Request: An audited ticket should be submitted by the technical team specifying the purpose, duration, and resources.
→ Approval (read-only): Temporary Read-only access required from EM’s or DevOps for troubleshooting.
→ Write/Emergency Access: Requires mandatory approval from our Director of Engineering for any sensitive write access for emergency fixes.
→ Execution: Sessions are logged, supervised and are adhered to the four-eye-principle (second approver). The access gets automatically expired after the approved duration.