Break the glass — loudly
Self-elevate to a sensitive capability under emergency controls: justification, step-up, a time box, and a SOC alert the whole team sees.
- 1
On the Break glass lab, write a real reason and activate.
A mandatory written justification is the first control — you cannot self-elevate silently, and the reason is recorded, not hidden.
- 2
If you have TOTP enrolled, notice you’re asked to step up first.
Break-glass demands a FRESH second-factor proof, enforced exactly like account erasure and secret rotation — enforce-only-when-enrolled, so a non-MFA account still proceeds.
- 3
Open the SOC dashboard and find the high-severity alert your activation just raised.
Every single activation trips a real ITDR detector, on purpose — "you can break the glass; you cannot do it quietly."
- 4
Read the privileged vault while the grant is live, then reseal it (or just watch the countdown expire).
The unlock is judged live against the grant’s expiry at read time, never trusted from a background sweep — the glass reseals itself, and every read is audited.
Learn the theory
🩻 X-ray — what actually happened
Your own insert-only audit trail — the real server events, sanitized (never a secret), each linked to the lesson that explains it.