Configure and Elevate Access for a PAM Cloud Resource
Configure JIT elevation and workflow settings for a PAM Cloud resource.
Last updated
Was this helpful?
Configure JIT elevation and workflow settings for a PAM Cloud resource.

This guide shows how to use a PAM Cloud record to grant just-in-time elevated access through the configured identity provider.
After the record is shared and JIT and Workflow are configured, users can request access, receive temporary group membership or role-based elevation for the approved time window, and launch the target platform without permanent standing privilege.
Use this setup when access to a cloud console or federated application is controlled by SSO, identity-provider groups, or role assignments and must be approved, time-bound, and fully auditable.
In the example below, a PAM Cloud record is configured to grant elevated access through the identity provider. Select Edit in PAM Settings to configure Workflow and JIT.

JIT settings define how access is granted after approval.
In this example, the record uses group-based privilege elevation.
The group name must exactly match the corresponding group in the identity provider.
After approval, the user receives temporary elevation for the configured duration.

Workflow settings define the approval controls for the record.
In this example, the record requires approval and limits access to 1 hour.
When the access window ends, any active session closes and the temporary elevation is removed.
You can also require a reason and ticket number with each request.
See Workflow for more information.

Once the PAM Cloud record is shared and JIT and Workflow settings are configured, the user can submit an access request from the Keeper Vault or from Commander.
See Keeper Privileged Cloud for the full workflow.
Last updated
Was this helpful?
Was this helpful?

