Control Packs · IDN-002 · v1.0.0
Temporary Privilege Expiry
Make privileged authority time-bound, purpose-bound, and independently visible when it crosses a dependency boundary.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Use scoped, time-limited privileged grants with approval, expiry, revocation, and failure visibility.
- Temporary authority becomes persistentA privileged integration retains access after the task, incident, or approval window that justified it has ended.
Versioned applicability rule
{
"all": [
{
"characteristic": "PRIVILEGED_ACTION",
"equals": true
},
{
"characteristic": "EXTERNAL_DEPENDENCY",
"equals": true
}
]
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- Which privileged operations require temporary approval and automatic expiry?The system must not assume that an external integration needs permanent authority.IDN-002-Q1 · scope
Requirements for the coding agent
- IDN-002-R1Separate privileged operations, require explicit approval, expire grants automatically, and record grant and revocation outcomes.
Tests and evidence to retain
- PRIVILEGE_EXPIRY_TESTVerify approval, allowed operation, denied operation, expiry, revocation, and dependency failure behavior.
- configuration_or_policy
- implementation_location
- test_result
- telemetry_definition
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- AC-2 · Account ManagementNIST_SP_800_53_5_2_0 · partially addressesApproval, expiry, grant, and revocation events address a defined privileged-access lifecycle; they do not cover all account management.
- AC-6 · Least PrivilegeNIST_SP_800_53_5_2_0 · partially addressesTemporary, purpose-bound privileged access limits authority; it does not establish complete least privilege.
- AU-12 · Audit Record GenerationNIST_SP_800_53_5_2_0 · partially addressesGrant and revocation events provide focused audit generation for privilege changes; they do not cover all audit records.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_LEAST_AUTHORITY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_AUDITABILITY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0