Break-Glass Access
Break-glass access is an emergency procedure that lets an authorized person gain elevated access rights they do not normally have, so they can respond to a crisis when standard access is insufficient. It works by temporarily bypassing the usual access controls, typically using pre-staged emergency accounts. The goal is to enable an effective response to emergencies without permanently weakening an organization's security.
Break-glass access is a controlled privileged-access mechanism that grants a principal elevated authorization rights in emergency situations by bypassing normal authorization controls that would otherwise deny or restrict that access. In most deployments it is implemented through pre-staged emergency accounts (as described in Source 4) that are held in reserve and made available with limited administrative overhead when standard access paths are unavailable or insufficient. This is an authorization-layer construct concerned with what elevated permissions are granted under exceptional conditions; the authentication of the individual invoking the procedure, along with associated logging, approval, time-bounding, and post-use review, are typically governed separately by organizational break-glass procedures and are out of scope for the core definition. The specific controls, account management practices, and safeguards vary by vendor, platform, and deployment context.
Why it matters
Break-glass access exists to resolve a fundamental tension in privileged access management: the same tight authorization controls that protect critical systems during normal operations can obstruct legitimate emergency response when standard access paths fail or prove insufficient. Without a pre-defined emergency mechanism, responders may resort to ad hoc workarounds, sharing credentials, disabling controls, or improvising elevated access, that leave no reliable trail and create lasting security gaps. A deliberate break-glass procedure lets an organization respond effectively to a crisis without permanently weakening its security posture.
Because break-glass by design bypasses the authorization controls that ordinarily deny or restrict elevated access, the mechanism itself becomes a high-value target and a potential single point of failure. Pre-staged emergency accounts hold powerful permissions and, if left unmonitored, can be misused or compromised. This is why the surrounding governance, authentication of the person invoking the procedure, approval, logging, time-bounding, and post-use review, matters as much as the access grant itself, even though those safeguards are governed separately from the core authorization construct.
For organizations operating under regulatory or contractual obligations, break-glass procedures often need to be documented, controlled, and auditable. In healthcare contexts, for example, emergency access to critical systems containing electronic protected health information (ePHI) is commonly managed through pre-staged emergency accounts precisely so that access can be granted quickly under exceptional conditions while remaining accountable after the fact.
Who it's relevant to
Inside Break-Glass Access
Common questions
Answers to the questions practitioners most commonly ask about Break-Glass Access.
