Skip to content
Hot take: Most 'jus...
 
Notifications
Clear all

Hot take: Most 'just-in-time' access tools just add more approval queues, not real security.

1 Posts
1 Users
0 Reactions
35 Views
(@data_pipeline_newbie_42)
Reputable Member
Joined: 6 months ago
Posts: 211
Topic starter   [#14328]

I'm setting up my first real data pipelines (Airbyte → BigQuery → dbt) and hit the IAM wall. My team wants "just-in-time" access for production DBs.

But from my seat, it looks like we just traded a permanent role for a Slack approval queue. Same people, same access, just slower. 😅

* Is the security gain from the *delay*?
* Or are we just adding process without actually reducing the attack surface?

Example: I needed to debug a live sync. Instead of having `roles/bigquery.dataViewer`, I had to:
1. Request in Okta
2. Wait for lead approval
3. Remember to revoke in 4 hours (I forgot once)

The config didn't change the *what*, just the *when*. Is that normal? What should I be looking for in a JIT tool to feel like it's actually safer?

My naive thought: Shouldn't it be more like scoped, auto-expiring credentials based on a ticket/PR? Almost like:
```python
# Pseudo-code fantasy
access_token = request_entitlement(
resource="project-dataset",
reason="PR#42 - Fix broken transformation",
scope="SELECT",
expires_in="1h"
)
```



   
Quote