break-glass account

expression

cloudsecurity

The sealed emergency credential that bypasses normal controls when identity itself is down - stored offline, alarmed on use, tested on schedule.

Named for the fire alarm: breaking the glass must work, and must never go unnoticed.

A break-glass procedure is the deliberately uncomfortable path to emergency access: credentials that normally nobody holds, released under a documented process, heavily logged, and reviewed afterwards. The name is from the fire alarm, and the analogy is exact, because the visible act of breaking something is part of the control.

The design tension is real. Access that is too hard to obtain means an outage extends while someone hunts for authorization, and access that is too easy stops being exceptional and becomes the normal path, at which point the control exists on paper only. The usual resolution is to make it fast but loud: obtainable in minutes, impossible to use quietly, and automatically generating a review that someone must complete.

Two failure modes are worth naming. Break-glass credentials that live in the system they are meant to recover are useless in precisely the scenario they exist for, which is why they belong somewhere independent. And a procedure never rehearsed is a procedure that will be discovered to be broken during the incident, so the exercise of actually using it, on a schedule, is what separates a real control from a documented intention.

All glossary entries