Security
Revocation and Evidence
How the work path, local preparation, closure reason, and records are read together after access closes.
Revocation consists of three separate operations: closing new launches, terminating active work, and withdrawing resource preparation when the connection model uses it. CerberusD keeps the result of each operation visible.
Three operations
| Operation | Effect | Verification |
|---|---|---|
| Remove assignment or let duration expire | Closes the person’s decision for new sessions. | The resource leaves the launchable list and a new request returns a closed result. |
| Terminate active session | Sends a closure command to running work. | Session state and the closure event update. |
| Withdraw resource preparation | Reverses managed local-account or connection preparation when used. | The Agent or gateway result appears with the resource record. |
Removing an assignment and terminating an active session serve different purposes. An authorized person closes active work separately when a session is already running.
Active-session flow
- Confirm the person, resource, and start time in the active-session view.
- An authorized role starts session termination.
- CerberusD dispatches the closure request to the running session path.
- A successful result moves the session into closure.
- Dispatch or runtime failure remains a visible result; assignment state is managed separately.
If termination fails or times out, the product does not mark the session as successfully closed. New launches are closed separately; the operator reviews the last session state and connection-path signal before a controlled retry or escalation. A retry does not erase the previous result; it appears as a separate event.
Closure time depends on the state of the connection path. The product links the termination request and received result to the record.
Close future access
After active work is handled, remove or expire the person-resource assignment. A later launch then requires a new assignment and decision. Use Close resource access when the entire resource is leaving operation.
Evidence result
The review view links:
- initiating person and authorized role,
- affected person and resource,
- assignment change,
- active-session termination request and result,
- closure time and reason,
- resource-preparation withdrawal result when present.
This page covers decision, assignment, session-lifecycle, revocation, and closure events. Session video, playback, and export are separate capabilities governed by enabled policy and retention configuration; lifecycle records do not imply video evidence.
When closure fails
- Remove or expire the assignment so new access cannot be opened.
- Read the active session’s last visible state and event in the panel.
- If the connection path is online, perform a controlled retry; if it is offline, use the gateway/Agent checks in connection troubleshooting.
- If the state does not change, add the resource identity, session identity, start time, termination-request time, and visible failure state to the support record. Keep passwords, tokens, and private connection values out.