This section captures the requesting engineer's identity and the specific cloud infrastructure impacted by the outage. Accurate metadata ensures proper accountability and enables security teams to correlate access with incident management systems.
Engineer Full Legal Name
Employee ID
Official Company Email Address
Direct Phone Number for Emergency Contact
Primary Team or Department
Are you currently the designated on-call engineer for this service?
Provide your on-call rotation identifier
Which cloud provider(s) are affected by this outage? (Select all that apply)
Amazon Web Services (AWS)
Microsoft Azure
Google Cloud Platform (GCP)
Oracle Cloud Infrastructure (OCI)
IBM Cloud
Alibaba Cloud
Other
Geographic regions impacted (Select all that apply)
North America (US East/West)
South America (São Paulo)
Europe (Frankfurt, Ireland, London)
Asia Pacific (Singapore, Tokyo, Sydney)
Middle East (Bahrain)
Africa (Cape Town)
Global (Multi-Region)
Specific Cloud Account/Subscription Details
Cloud Provider | Account ID/Subscription ID/Project ID | Account Alias or Description | Organizational Unit (OU) or Management Group | ||
|---|---|---|---|---|---|
A | B | C | D | ||
1 | |||||
2 | |||||
3 | |||||
4 | |||||
5 | |||||
6 | |||||
7 | |||||
8 | |||||
9 | |||||
10 |
Resource types directly affected by the outage (Select all that apply)
Compute (EC2, VMs, GCE)
Container Orchestration (EKS, AKS, GKE)
Serverless Functions (Lambda, Azure Functions)
Database (RDS, Cosmos DB, Cloud SQL)
Storage (S3, Blob Storage, Cloud Storage)
Networking (VPC, VNet, VPC)
Identity & Access Management (IAM, AD)
Monitoring & Logging (CloudWatch, Monitor)
Other
Provide specific resource identifiers (ARNs, resource IDs, instance IDs) affected
Your Current IAM Role or Permission Set
Primary Incident Ticket Number
Change Request Reference (if applicable)
Peer Engineer Contact for Verification
This section establishes the criticality of the incident and provides context for the urgency of elevated access. The severity assessment directly impacts approval urgency and monitoring protocols. Be precise about business impact to justify permission elevation.
Official Incident Severity Level
P1-Critical: Complete service outage affecting all users with no workaround
P2-High: Major functionality impaired, significant user impact, limited workaround
P3-Medium: Partial service degradation, moderate user impact
P4-Low: Minor issue, minimal user impact, standard workaround available
Outage Start Timestamp (UTC)
Estimated Time to Resolution (in minutes) WITHOUT elevated permissions
Approximate Number of End Users Affected
Estimated Revenue Impact per Hour (USD)
Does this outage pose compliance or regulatory violation risk?
Which regulatory frameworks are at risk? (Select all that apply)
GDPR
HIPAA
PCI-DSS
SOC 2
ISO 27001
SOX
Other
Which specific services or APIs are non-functional or degraded? (Select all that apply)
Customer-facing web application
Mobile app backend APIs
Payment processing system
Authentication/Authorization service
Data pipeline/ETL processes
Real-time messaging/streaming
Administrative/management console
Third-party integrations
Other
Is the root cause of the outage already known?
Describe the identified root cause and why elevated permissions are required to remediate
Describe your current troubleshooting approach and why elevated permissions are critical for diagnosis
Describe all remediation attempts already performed with standard permissions
Detailed Business Justification for Elevated Access
Customer Impact Description
Will this outage breach contractual SLA commitments?
Has this been escalated through your standard management chain?
Name and title of manager aware of this request
This section defines the exact elevated permissions being requested and the temporal boundaries for access. Precision is critical: overly broad permissions increase security risk, while overly narrow permissions may impede resolution. Specify exact IAM roles, policies, or permissions needed.
Exact IAM Role Name(s) or Permission Set(s) Required
Specific Cloud Permissions Required (Action-Level Detail)
Service Name | Specific Permission Action (e.g., ec2:TerminateInstances) | Resource Scope (ARN or ID) | Justification for This Specific Permission | ||
|---|---|---|---|---|---|
A | B | C | D | ||
1 | |||||
2 | |||||
3 | |||||
4 | |||||
5 | |||||
6 | |||||
7 | |||||
8 | |||||
9 | |||||
10 |
Requested Access Start Time (UTC)
Requested Access End Time (UTC)
Maximum Session Duration Before Re-authentication Required
1 hour
2 hours
4 hours
8 hours (full shift)
12 hours
24 hours (only for extended complex remediation)
Is this a break-glass emergency scenario where normal approval workflows are bypassed?
Explain why break-glass protocol is necessary and what immediate threat requires bypassing standard approval
Emergency Contact During Elevated Access Session
Will you be using any shared or emergency credentials during this session?
Specify which shared credentials and the controlled method for obtaining them (e.g., password vault checkout)
Do specific commands or scripts require pre-approval before execution?
List commands/scripts that require real-time approval and identify who can approve them
Upload any scripts or automation documents planned for execution during elevated session
Step-by-Step Plan of Actions to be Performed with Elevated Permissions
This section establishes the mandatory oversight mechanisms to ensure all elevated actions are transparent, traceable, and subject to real-time security monitoring. These protocols are non-negotiable for temporary permission elevation and enable post-incident forensics.
Is comprehensive audit logging (e.g., AWS CloudTrail, Azure Activity Log) already enabled for all affected resources?
Explain why logging is not enabled and what alternative monitoring will be used
Real-Time Monitoring and Alerting Mechanism
SIEM integration (Splunk, QRadar)
Cloud-native monitoring (CloudWatch Logs, Azure Monitor)
Dedicated privileged access monitoring tool
Manual security team observation
Other
Notification channels for security team monitoring (Select all that apply)
Email alerts
Slack/Teams channel messages
SMS notifications
PagerDuty/Opsgenie alerts
Direct phone call to SOC
Webhook to security automation platform
High-Risk Commands Requiring Real-Time Approval
Command Pattern (e.g., 'kubectl delete namespace') | Approver Name | Approver Contact | Pre-Approved for This Session? | ||
|---|---|---|---|---|---|
A | B | C | D | ||
1 | |||||
2 | |||||
3 | |||||
4 | |||||
5 | |||||
6 | |||||
7 | |||||
8 | |||||
9 | |||||
10 |
Will your entire elevated session be screen-recorded for audit purposes?
Justify why screen recording is not feasible and describe alternative capture methods
Session Recording Method
Native cloud session manager (AWS Session Manager)
Privileged Access Management (PAM) tool
Third-party screen recording software
Terminal session logging (script, tmux)
Video conference recording (Zoom, Teams)
Will all executed commands be logged to a central immutable log repository?
Describe Automated Alert Thresholds (e.g., alert on 'delete' commands, mass data access)
Has the Security Operations Center (SOC) been notified of this potential elevated access request?
SOC Ticket or Reference Number
Will the Incident Response team be actively monitoring this session?
Post-Access Log Review Plan
Final authorization for temporary elevated permissions must be granted by the Chief Information Security Officer or designated approver. This section captures the formal risk assessment and approval, establishing accountability at the highest security level. Approval is contingent upon satisfactory completion of all preceding sections.
CISO or Designated Security Officer Full Name
CISO Official Email
Overall Risk Assessment Score (1=Minimal Risk, 5=Extreme Risk)
Alternative Solutions Considered Before Approving Elevated Access
Why Standard Permissions and Processes Are Insufficient for This Incident
Do you formally approve this temporary elevated access request?
Specify any conditions or restrictions on this approval (e.g., time-limited further, restricted to specific resources only)
Provide detailed rejection rationale and recommend alternative remediation approach
CISO Digital Signature
Official Approval Timestamp (UTC)
Additional Security Conditions or Exceptions Granted
I acknowledge that this approval creates a temporary security exception and that a post-incident review will be mandatory to prevent future occurrences
To configure an element, select it on the form.