Guides
Close resource access
How to stop a resource from launching new sessions, remove assignments, and verify closure evidence.
This guide closes the resource’s launchable work path in CerberusD. Use Revocation and evidence when access is changing for one person only.
Prerequisites
- A role that can revoke access for the resource.
- Resource name, protocol, and last intended use.
- Access to the active session and evidence views.
- Operational context for stopping managed local-account preparation when used.
- A way to confirm resource identity and last-seen state before closing access.
Before you begin
Closing resource access can have persistent impact. Answer these questions first:
- Is there an active session?
- Are people or roles still assigned to this resource?
- Does another workflow depend on the resource?
- Is managed local-account preparation active?
- Is the resource connection removed from access, or only suspended?
If the answer is unclear, remove the assignment first and block new sessions. Treat changes to the resource connection as a second step.
Steps
- Find the resource. Select the correct row by name, protocol, last-seen state, and purpose.
- Check active sessions. If a session is open, close or revoke it before removing the launch path.
- Remove assignments. Block new launch decisions by removing person-resource assignments.
- Stop local-account preparation. If managed local-account preparation is used, confirm it no longer creates a launch path for the resource.
- Close the connection path. Disable the agent/gateway record, RDP resource, or connection definition when it will no longer be used.
- Verify visibility. The resource no longer appears as launchable for assigned users.
- Review evidence. Confirm assignment removal, active session closure, and resource access closure are distinguishable in the record flow.
Expected result
The resource stops producing new launchable sessions and leaves the launchable list. Active-session closure and resource-path closure remain separate events in the record.
Failure notes
The resource still appears when the inventory record remains for history but no launch path exists. Distinguish historical visibility from launchability.
The session remains visible after closure when the connector or session gateway reports state late. Review active session state, last event time, and revocation evidence together.
The wrong resource was selected. Stop the change. Use an authorized role to evaluate access closure or assignment restoration for the affected record.