Access control
Per target you decide whether sign-in is free, needs a justification, needs another colleague's approval, or is denied. The system recomputes the decision before every connection, and can tell you afterwards who let whom in.
Four grades, one source of decisions
The decision is computed from the zone matrix: a user gets the most permissive cell among their groups, and where there is no cell, the answer is Denied. An empty matrix, an unknown zone or an unknown group therefore never produces wider access.
| Grade | What happens, and what an auditor sees |
|---|---|
| Denied | The target does not appear in the user's list, and the server refuses the connection request too. In the report an auditor sees that the verdict for that zone, group and access level is Denied. |
| Approval required | The user files a request with a planned start time, and can sign in only once another approver has granted it. An auditor sees who decided the request, when, and for which time window. |
| Justification required | The user can sign in, but has to state a reason first. In the review report an auditor sees who signed in at this grade, when, and why. |
| Free | The user connects in one click, with no request and no justification. The connection is logged just the same, so this grade is not a blind spot either. |

Justification required: lets people in, and leaves a trace
This grade does not keep the user out, it makes the sign-in traceable. Before connecting they state a reason, and the tiles show which targets fall into this grade before anyone clicks. One justification covers a session: the system does not ask again for the same connection. The review report shows who signed in at this grade, when and why, so periodic access review does not need a round of interviews.
Approval required: a pre-approved time window
No self-approval
A user's own request never appears on their own approval queue, and if the requester posts a decision straight to the server, the server refuses it too. The requester is notified of the decision.
No workaround
If nobody decides, there is no access: it does not open after a grace period, and there is no emergency back door. If a target needs immediate access, give it the Justification required grade instead.
The window expires
The approval covers the requested window, and a late decision does not push its end back. After expiry no new connection opens, though a session already running is not cut off.
A granted access can be revoked
Revoking also offers to close the session running on the target, but that is a separate choice and it is not ticked by default. A reason is mandatory. The decision and its reason reach the user too, so they do not walk into a silently closed door the next time they connect.
The zone separation report
Per zone, group and access level, the admin report puts side by side what the matrix stores and what the evaluator actually grants, and lists where the verdict is Denied. It is the evaluator's real output rather than a settings screen, and it exports to CSV, so it can be handed over as evidence.
The log says who let someone in
At the Approval required grade the decision sits next to the request: who decided it, when, and whether it was granted. At the Justification required grade the stated reason is recorded, and on a revocation the reason for revoking. Who let somebody into a zone is never a question answered from memory.
Network access · Security and architecture · NIS2 and CRA · Pricing