Teams start bypassing the control to keep the plant running, which usually recreates standing privilege through exceptions and manual approvals. JIT only works when it matches how maintenance, support, and emergency access actually happen in OT.
Why JIT Breaks When It Does Not Fit the Maintenance Workflow
Just-in-time access fails when it is designed around the policy ideal instead of the operational rhythm of maintenance. If technicians, vendors, and control-room staff cannot get the right access quickly enough for planned work, fault response, or safe shutdown windows, they route around the control. The result is not tighter privilege, but friction that pushes teams back toward exceptions, shared accounts, and manual approvals.
The core issue is that maintenance work is bursty, time-sensitive, and often dependency-heavy. Access has to line up with shift handoffs, permit-to-work processes, remote support windows, and the reality that some tasks cannot wait for a slow approval chain. When JIT does not reflect those patterns, the control becomes an obstacle rather than a safeguard.
That is why the best JIT designs treat workflow fit as a control requirement, not a convenience feature. A good model still enforces privileged access management, but it does so through access windows, session controls, and clearly defined activation paths that match how maintenance is actually performed.
What Users Do Instead of Following the Control
When the access path is too slow or too brittle, operators optimize for uptime. They ask for broader standing access, keep privileged accounts open “just in case,” or rely on manual escalation every time a task repeats. That behaviour is understandable in operations, but it quietly undoes the point of JIT by reintroducing persistent privilege through the exception process.
This is especially common where there is a gap between planned maintenance and unplanned intervention. Planned work can tolerate a request-and-approve step; urgent troubleshooting usually cannot. If the access model does not distinguish those two modes, teams end up using the same workaround for both, which expands privilege beyond the original intent.
In practice, the failure is often not the absence of access control but the absence of a usable operating model. A JIT program has to reflect emergency access, vendor support, and routine maintenance separately, or it will be bypassed the first time the plant is under pressure. Break-glass and emergency access should be explicit, tested, and distinct from normal maintenance activation.
How to Align JIT to Maintenance Without Recreating Standing Access
The practical fix is to align access activation to the real work pattern, not to one generic approval flow. For repeat maintenance, that usually means role-based eligible access, short activation windows, pre-approved task scopes, and logging that is tied to the work order or change ticket. For vendors and remote support, it means tighter expiry, session oversight, and a narrower permission set than the one used by internal engineers.
JIT also has to account for credential type. In OT, maintenance may involve service accounts, equipment interfaces, or remote support credentials that cannot be handled like a normal human login. Where machine or service access is involved, lifecycle, rotation, and ownership matter as much as the activation event itself. Service account governance becomes part of the JIT design, not an adjacent housekeeping task.
Where access must be temporary but frequent, the cleanest pattern is to separate “eligible for access” from “currently active.” That is the practical line between zero standing privilege and uncontrolled permanent privilege. It lets maintenance teams move quickly without leaving broad access enabled between jobs, and it reduces the temptation to solve an access problem by making an exception permanent. Just-in-time access and zero standing privilege works best when activation is time-bound, auditable, and tied to a real task.
Risk and Threat Considerations
Misaligned JIT creates a security exposure that grows over time. The immediate problem is bypass behaviour, but the deeper risk is that exceptions become the normal operating path and the environment drifts back to standing privilege, shared credentials, and weak accountability. In OT, that increases both the attack surface and the chance that a rushed workaround survives long after the maintenance event.
Failure mechanism: Access requests that are too slow, too rigid, or too detached from maintenance reality drive teams to bypass activation controls, reuse open sessions, or keep exception accounts alive so work can continue uninterrupted.
Impact: The organisation loses the intended blast-radius reduction, and privileged access becomes harder to review, harder to revoke, and easier to abuse during both routine operations and incident conditions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | JIT and exception access depend on controlled account activation and revocation. |
| AC-6 — Least Privilege | The question is about standing privilege reappearing when JIT is misaligned. | |
| IA-5 — Authenticator Management | Maintenance workflows often rely on credentials, shared access, and rotation-sensitive secrets. | |
| Recommendation — Define eligible, active, and expired access states and revoke exception access promptly. Limit maintenance access to the minimum privileges needed for the specific task. Manage maintenance credentials with expiry, rotation, and secure storage. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | JIT alignment is an access control and exception-management problem. |
| CIS-5 — Account Management | Recurring maintenance access needs ownership, lifecycle, and exception discipline. | |
| Recommendation — Review, grant, and remove maintenance access through a controlled, time-bound process. Inventory maintenance accounts and retire unused or permanent exception accounts. | ||
Practitioner Guidance
What to prioritise: Start by mapping the real maintenance lifecycle, including planned work, emergency repair, vendor support, and shift handoff. If one approval flow is being forced to cover all four, the model is already misaligned.
What to verify: Confirm that every recurring maintenance scenario has a defined activation path, expiry rule, and owner, and that exceptions do not become an informal standing access tier.
Common mistake: Treating JIT as a procurement or policy exercise instead of an operations design problem. If the plant cannot run safely inside the control, people will work around the control.
Practitioner takeaway: JIT only improves security when it reduces privilege without reducing the organisation’s ability to perform work, so the real test is whether maintenance teams can use it under pressure without reaching for permanent exceptions.
Related resources from NHI Mgmt Group
- When do NHI access reviews create more value than a one-time cleanup?
- What breaks when just-in-time access is added on top of old PAM workflows?
- What breaks when privileged access modernization is not aligned to DevOps workflows?
- What breaks when secure access is not aligned with frontline clinical workflows?