Concepts

Access problems and operational answers

A source-backed catalog of common access-operations problems, and how CerberusD handles them through governed workspaces, sessions, revocation, and evidence.

Page type: ConceptAccess problemsStatus: CurrentCurrent product behaviorLast reviewed: 2026-07-26

Access operations involve more than starting a session. The person, workspace, resource, duration, and evidence are governed together. This catalog maps common operational problems to the CerberusD model.

Current risk context

Valid credentials and remote access surfaces continue to appear together in current incident research:

These findings support governing access through credential custody, resource scope, duration, active-session control, and closure.

Shared accounts and credentials

Problem

Shared accounts and passwords separate the person doing the work from the resource account. Password circulation and later account changes weaken the chain of responsibility.

Cerberus approach

The person reaches an assigned work surface with their own identity. Local resource accounts and credential flow operate without requiring the operator to see the password.

Operational result

The action is tied to the person and assigned resource; password sharing and copying leave the normal work path.

Per-resource network and tool sprawl

Problem

Separate VPN profiles, clients, and protocol tools multiply access paths and make the intended work surface harder to identify.

Cerberus approach

Resources remain in their own environment. Workspace, assignment, and readiness come together in one access decision, followed by a browser session or controlled private access path.

Operational result

People reach the assigned work surface instead of holding standing access to the whole network; daily switching between protocol-specific tools is reduced.

Firewall and port-exposure burden

Problem

Opening RDP, SSH, or similar resource ports for external access creates firewall rules, exceptions, and maintenance work. Each open port adds an access surface.

Cerberus approach

The access decision does not depend on turning the resource into an openly reachable target. Resource readiness and the assigned session path are evaluated without leaving resource ports continuously open to the operator.

Operational result

Teams reduce port exceptions and broad network reachability; access is operated through resource and session scope.

Person, scope, and user management

Problem

When signing in is treated as access to every resource, the boundaries between person, role responsibility, resource scope, and duration become unclear.

Cerberus approach

The session decision evaluates identity, role responsibility, workspace, assigned resource, duration, and readiness together. An unassigned resource does not become a visible, startable work surface.

Operational result

User management stays connected to resource scope; a missing or expired decision does not create a broader access path.

Time-bound access and closure

Problem

After maintenance or external support work ends, separately tracking access can leave an open session or forgotten exception in place.

Cerberus approach

Access decisions carry duration and scope. Sessions can close, access can be revoked, and revocation closes the path to a new session.

Operational result

Temporary work does not become standing authority; closure and revocation remain in the same operational flow.

Who accessed what and when

Problem

When it is unclear which person started work on which resource and at what time, investigation and accountability take longer.

Cerberus approach

The access decision and session lifecycle are recorded with person, resource, protocol, start, state changes, and closure context.

Operational result

Review starts from the decision and session lifecycle record instead of reconstructing events from scattered notes.

Scattered logs and evidence

Problem

When the access decision, session state, and revocation record live apart, reconstructing the full event becomes difficult.

Cerberus approach

Decision, session, revocation, and closure events are related in one evidence model. The current evidence scope covers lifecycle and decision events. The video or screen recording, playback, and export surface remains in development.

Operational result

Operations can review what opened, when it closed, and how access was revoked in one context.

External support access

Problem

Opening broad, long-lived network access for external support puts work and unrelated resources on the same surface.

Cerberus approach

The support task is assigned to a specific person, workspace, resource, and duration. The support session can close and access can be revoked.

Operational result

Support stays limited to the required resource; closing the work does not require a separate hunt for open access.

Active-session visibility and closure

Problem

When active sessions are not visible, it is unclear whether access remains open or which work is still running.

Cerberus approach

The session lifecycle remains visible. An authorized action can close the session or revoke access from the same management flow.

Operational result

Operations can see active work, close it when required, and review the closure time as evidence.

Workspace and resource boundaries

Problem

When resource lists and access decisions escape workspace boundaries, a person can see or start a resource from another workspace.

Cerberus approach

Access decisions stay within workspace scope. A mismatch between resource, person, and assignment does not widen the decision.

Operational result

Resource inventory and sessions stay in the correct workspace; a boundary violation produces a visible denial or error state.