Skip to content
Lorca Labs
Live demo
Compliance

Break-Glass Envelope

Emergency access that exists when you need it — and leaves a permanent record the moment it is used.

The problem

Emergency access exists so critical systems stay reachable in a crisis — but standing access is exactly what attackers want and auditors question.

What it does

01

Seals emergency credentials behind a tamper-evident envelope.

02

Breaks the seal only with a recorded reason — releasing the payload.

03

Lists envelopes by status (sealed or broken).

04

Audits every break: who, when, and why.

Who it’s for

  • SRE and on-call teams holding emergency credentials
  • Security teams that need a break-glass record
  • Compliance teams auditing emergency access

In context

The audit feed pairs with the AI Decision Audit Trail — every break is a governance event.

Spec & limits

Interface Input limits Output artifact Failure mode Non-claim
Studio ephemeral /demo; pilot durable /v1 on your infrastructure. TBD — verified in pilot acceptance TBD — verified in pilot acceptance TBD — verified in pilot acceptance TBD — verified in pilot acceptance

Related guide

See the break-glass access audit guide for a deeper problem walkthrough and verification notes — evaluation notes for the live demo and for a private pilot. Also: try the live experiment and read the product overview.

Frequently asked questions

/ 05
01 What is sealed by default, and how is it released?

The emergency credential is stored sealed until an authorized actor records a release reason; only then is it decrypted and an audit entry emitted.

02 Who can break glass — a single actor or requires approval?

Configurable — single-actor release or a multi-party approval threshold; the policy and the release are both recorded.

03 Is the break-glass event recorded immutably?

Yes — the release emits a signed, hash-chained receipt with who, when, and why; the event cannot be deleted from the audit trail.

04 Can a break-glass release be automated for incidents?

Releases require an actor and a recorded reason by default; automated rotation or alerting is wired to the receipt, not to silent credential release.

05 How does this differ from a password vault emergency access?

It focuses on the audit record — sealed by default, released only with a recorded reason — rather than on credential storage or rotation mechanics.

Try it live in the studio

A no-signup, in-browser experiment against an isolated demo host. Load sample data, run the flow, and see the result — nothing is stored.