Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Ephemeral cloud access in the browser, are PAM workflows finally usable?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15737
Topic starter  

TL;DR: The biggest barrier to privileged cloud access is workflow friction, not policy, according to Britive, and embedding ephemeral JIT access and approvals directly in the browser can reduce ClickOps resistance across AWS, Azure, and GCP. The underlying issue is that traditional PAM often fails because controls that interrupt the engineer’s flow get bypassed or automated around.

NHIMG editorial — based on content published by Britive: Eliminating Security Friction: Enabling Ephemeral Cloud Access Directly in the Browser

By the numbers:

Questions worth separating out

Q: How should security teams implement JIT access in multi-cloud environments?

A: Security teams should build JIT into the access workflow itself, not bolt it on after approval.

Q: Why do privileged access workflows get bypassed in DevSecOps teams?

A: Because the control path often interrupts the engineering task more than it protects it.

Q: What breaks when access approvals require a separate identity portal?

A: Approval latency increases, context gets lost, and managers are more likely to approve mechanically just to unblock work.

Practitioner guidance

  • Map the access path engineers actually take Trace how cloud console elevation is requested, approved, and consumed today, then identify every point where users leave the primary workflow.
  • Validate that ephemeral checkout is truly time-bound Confirm that the temporary permission is minted through native cloud APIs, expires automatically, and cannot be reused after the task window closes.
  • Move approvals into the engineer's working surface Let approvers review context and approve or deny requests without switching to a separate identity portal.

What's in the full article

Britive's full blog covers the operational detail this post intentionally leaves for the source:

  • Browser-extension workflow mechanics for Chromium-based browsers and Firefox.
  • Step-by-step access checkout and approval flow for AWS, Azure, and GCP consoles.
  • How native cloud APIs mint temporary permissions in the background.
  • Practical examples of how approvers can review context without portal switching.

👉 Read Britive's analysis of browser-embedded ephemeral cloud access →

Ephemeral cloud access in the browser, are PAM workflows finally usable?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15322
 

Browser friction is an identity control problem, not just a user-experience problem. PAM tools that force engineers out of their work surface create the conditions for bypass, because policy that interrupts delivery is treated as optional in practice. The control can be technically sound and still fail operationally if the workflow is too expensive to use. That makes workflow design part of identity governance, not a separate usability concern.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when cloud access is over-granted and not removed?

A: Accountability usually sits across IAM operations, application owners, and line-of-business managers, because each has part of the lifecycle. The programme fails when nobody owns the removal step. In mature governance, access approval and access removal are both explicitly assigned and reviewed.

👉 Read our full editorial: Browser-embedded ephemeral cloud access changes PAM adoption



   
ReplyQuote
Share: