How to give temporary access
When one person needs one extra permission for a limited time, use a direct grant instead of putting them in a group. Grants always expire, which is what keeps temporary access from quietly becoming permanent.
Prerequisites
iam:grant:createto create,iam:grant:renewto extend,iam:grant:revoketo cancel.- You can only grant a permission you hold yourself, on the target you are granting it.
Create a grant
Open IAM, go to the Grants tab and click Create grant. The wizard has seven steps:
- User: who receives it.
- Permission: the single permission being granted.
- Scope: the level it applies at. Unlike a group, a permission is not tied to one level, so you choose it here from the levels the permission allows.
- Target: which customer or VDC, when the scope needs one.
- Expiration: the date it stops working. Mandatory, and it has to be in the future.
- Governance: the reason, recorded in the audit log.
- Review: check and confirm.
The permission applies on the person's next token refresh, within about five minutes.
Extend a grant
Open the grant from the Grants tab to reach its detail page, then choose Renew and fill in the New expiration date.
Two rules apply:
- The new date has to be later than the current one. To shorten access instead, revoke the grant and create a new one.
- You can only renew a grant that is still valid. Once it expires, the option disappears and the platform refuses the renewal. An expired grant cannot be revived, so create a new grant instead.
That second rule is the one to plan around: if the access must continue, renew it before the expiry date, not after.
Revoke a grant
On the same detail page, choose Revoke grant. It stops counting immediately, and the record stays visible for auditing. A grant that is already revoked cannot be revoked again.
Notes
- Grants expire on their own. There is no cleanup to do afterwards.
- The list marks each grant as active, expiring, expired or revoked, so an expired one stays visible instead of disappearing.
- If several people need the same exception, that is a group, not a set of grants. Grants scattered across users are what makes access impossible to review later.
- The Permissions tab on a person shows grants merged with group permissions, and marks which is which.