BEAM · TIME-BOUND ACCESS

Access that ends on its own.

People ask for what they need, someone approves, and the access is created for a set time and removed when it ends. Databases, servers, clusters, cloud accounts, GitHub, Slack and Linear, all the same way.

Time-bound access on Pro · governance on Business

THE USUAL WAY

Who still has access to production?

Access is usually granted in a hurry and removed by memory.

Admin rights given 'for a day' are often still there months later.
One shared key or password often opens the server for everyone.
A contractor leaves; Slack, Linear and GitHub often still let them in.
An auditor asks who could reach production last quarter, and nobody can answer quickly.
What you are seeing
  1. 01Dana asks for access
  2. 02An approver is asked
  3. 03Access is created
  4. 04Dana connects
  5. 05Time runs out
  6. 06Servers use certificates
  7. 07Everything on record

Example data.

How it works

Ask, approve, expire

01

Owners decide what can be asked for

Each target has a maximum duration. Owners can set a lower cap for that target.

Example data.

02

People ask with a reason

A request names the target, level, duration and reason. Someone with permission to approve Beam requests is emailed and approves it.

Example data.

03

It ends on its own

The access is removed automatically when its time ends. An owner can revoke it early.

Example data.

One request model

Every system, the same way

A person asks with a reason, someone approves, and the access ends at its limit. Choose a system to see what is created and removed.

What Zaysa creates

A temporary role is created on the database for PostgreSQL, MySQL, MongoDB or Redis.

What happens when it ends

The temporary role is dropped automatically when access expires or an owner revokes it.

Longest default: 90 days

Example data.

Duration caps

As long as it needs, no longer

Each system has a maximum duration. People can only choose a preset within that cap. Owners can lower the cap for a target.

Choose a target

Choose a duration

Longest for this system: 7 days

Owners can set a shorter cap for any target.

Example data.

ON THE BUSINESS PLAN

See and clean up every access

Time-bound access is on Pro. Access governance adds the view and clean-up tools on Business.

Access Map

See every person and every system they can reach. Recertify each grant: keep or revoke.

Example data.

Access Activity

Every request, approval and live session in one list.

Example data.

Offboarding in one step

Remove a person's access across every system, then review the resources and cost they leave behind. Running infrastructure is never stopped.

Example data.

Standing Credentials

Long-lived AWS access keys, console logins and cross-account roles, plus GitHub members and outside collaborators, tied to a person and flagged when the owner has left.

Example data.

Questions

Frequently asked questions

Time-bound access to databases, SSH servers, Kubernetes and OpenShift clusters, cloud accounts, GitHub, Slack, Linear and a one-time deploy pass.

More in Beam

See what you run, and what it costs.

Free plan, no card needed.