Abstract: A set of one or more permissions associated with an identity is determined. One or more risk metrics and corresponding usage associated with the one or more permissions associated with the identity are determined. Access associated with at least one permission from the set of one or more permissions associated with the identity is modified based on the one or more determined risk metrics and corresponding usage associated with the one or more permissions associated with the identity.
Abstract: A just-in-time (JIT) elevated privilege access request associated with a user is analyzed including by using a plurality of factors associated with an impact of approving the request. It is determined whether to approve the request based on the analysis. A JIT session with elevated privileges is provisioned based on the determination.