Skip to main content

How to give temporary access

When one person needs one extra permission for a limited time, use a direct grant instead of putting them in a group. Grants always expire, which is what keeps temporary access from quietly becoming permanent.

Prerequisites​

  • iam:grant:create to create, iam:grant:renew to extend, iam:grant:revoke to cancel.
  • You can only grant a permission you hold yourself, on the target you are granting it.

Create a grant​

Open IAM, go to the Grants tab and click Create grant. The wizard has seven steps:

  1. User: who receives it.
  2. Permission: the single permission being granted.
  3. Scope: the level it applies at. Unlike a group, a permission is not tied to one level, so you choose it here from the levels the permission allows.
  4. Target: which customer or VDC, when the scope needs one.
  5. Expiration: the date it stops working. Mandatory, and it has to be in the future.
  6. Governance: the reason, recorded in the audit log.
  7. Review: check and confirm.

The permission applies on the person's next token refresh, within about five minutes.

Extend a grant​

Open the grant from the Grants tab to reach its detail page, then choose Renew and fill in the New expiration date.

Two rules apply:

  • The new date has to be later than the current one. To shorten access instead, revoke the grant and create a new one.
  • You can only renew a grant that is still valid. Once it expires, the option disappears and the platform refuses the renewal. An expired grant cannot be revived, so create a new grant instead.

That second rule is the one to plan around: if the access must continue, renew it before the expiry date, not after.

Revoke a grant​

On the same detail page, choose Revoke grant. It stops counting immediately, and the record stays visible for auditing. A grant that is already revoked cannot be revoked again.

Notes​

  • Grants expire on their own. There is no cleanup to do afterwards.
  • The list marks each grant as active, expiring, expired or revoked, so an expired one stays visible instead of disappearing.
  • If several people need the same exception, that is a group, not a set of grants. Grants scattered across users are what makes access impossible to review later.
  • The Permissions tab on a person shows grants merged with group permissions, and marks which is which.