- Role
- db-break-glass
- Target
- prod-db-01
Make sure your AI only gets the access an admin approved.
Your access tool can't prove what the approver saw. OmniArx signs the exact role, target and command on their phone.
- Role
- db-break-glass
- Target
- prod-db-01
Anything different is refused before it reaches your API.
Where a yes has to be proven.
Your access tool already has an approval step. It cannot prove what the approver saw. Session recording shows what happened afterwards, not what was approved.
- Target
- prod-db-01
- Run as
- db-admin
- Person
- Sam Rivera
- For
- 1 hour
- Table
- customers
- Target
- prod-db-01
How it works.
The agent asks
Your agent or engineer asks for access. Nothing opens yet. The approval screen is built from the access request itself.
The person answers
The approving admin sees the role, target and command on their phone and slides to approve, then confirms with a fingerprint or face. Only then does the phone sign exactly that.
The API checks
The check in front of your access system compares the signed request with the real one. A swapped command or a reused approval is refused.
Tested against a real access tool.
Measured against a real open-source access tool. A swapped command was refused. A reused approval was refused.
- An access tool grants a role for a time window, not one command. OmniArx proves the approval. It does not limit what runs inside that window.
- We do not replace your access tool. Commercial access tools are not integrated yet.
- Each approval works once and expires within minutes.
Bring the action
you want to protect.
Tell us what your agent does and which system it calls. We will map the route, the approval screen and where the check goes.
Book a session