The worst possible time to discover that an engineer doesn’t have production access is during a live incident.
The second worst is six months later, when we discover they still have it.
This growing security issue sits squarely between incident management and identity and access management. When something breaks at 3:00 a.m., the person responding needs enough privilege to act. To investigate, change configurations, restart services, inspect logs, and restore operations. A ticket waiting impatiently in somebody’s morning queue isn’t useful. Heroes can’t be heroes without access to the right tools.
But granting permanent administrative access to everyone who might someday be on call isn’t good practice. It replaces an operational delay with a persistent security risk.
Our Trustle Rootly integration connects these two worlds by using the current on-call status to determine when privileged access should be automatically granted and, equally important, when a human needs to get eyes on important decisions. Simple.
Rootly gets the right responder into the incident
Modern incident response isn’t about phoning whoever drew the short straw that week. Rootly brilliantly combines on-call schedules, alert routing, escalation policies, incident workflows, communications, automation, and retrospectives across the incident lifecycle. Heck, we use it ourselves.
Outages (or even branches) move quickly. Rootly’s guidance talks about on-call platforms as reliability infrastructure rather than just scheduling utilities. They decide who should be contacted, how incidents escalate, and what operational context responders receive.
The latest NIST incident response guidance, published in April 2025, treats incident response, which is often an IT incident, as part of ongoing cybersecurity risk management. Response efficiency isn’t an isolated help-desk metric. It affects how effectively we detect, contain, recover from, and learn from security events.
Rootly can establish who should respond. The question is what that person should be allowed to do.
On-call responsibility doesn’t require permanent privilege
Many organizations solve emergency access by granting (often breakglass) production privileges in advance. The logic is understandable: incidents don’t keep office hours, and nobody wants a midnight access request blocked because an approver is asleep.
The problem is that “might need access” can become “always has access.”
Those privileges remain available between shifts, during vacations, after team changes, and long after the original justification has disappeared. This is classic privilege drift: reasonable access gradually becomes unnecessary access, usually without anybody making a deliberate decision.
It also conflicts with the principle of least privilege. Access should reflect the work being performed now, not every task an identity could conceivably perform during the next financial quarter.
Attackers are quite happy with the older arrangement. Stolen credentials don’t become harmless because the legitimate account owner isn’t currently on call.
Rootly schedules become access context
With the Trustle integration, Rootly’s scheduling data becomes a trusted input for access decisions.
When an on-call shift begins, Trustle can automatically provide the responder with the cloud or SaaS privileges required for incident handling. When the shift ends, those permissions are removed. This applies just-in-time access to the actual operational schedule rather than relying on permanent roles, manual reminders, or hopeful calendar management.
The basic workflow:
- Rootly identifies the current on-call responder.
- Trustle grants time-bound access to anything the responder requests, without leaving Slack.
- The responder investigates and resolves incidents.
- Trustle revokes access when the shift ends (or can grant a time-boxed extension automatically, on request).
- The access event remains visible for review and audit.
That reduces access friction without creating another population of permanently privileged users. It’s the difference between opening a door when somebody arrives and leaving it open all week because they may come back.
Shift changes shouldn’t break access controls
Real on-call schedules change. People swap shifts, take leave, cover emergencies, and are occasionally required to attend a family dinner.
Static access assignments don’t adapt well to this. They require administrators to reproduce every scheduling change in a separate identity system, which is tedious, fragile, and exactly the sort of task humans perform well until human mistakes are made.
The Rootly integration allows Trustle to account for schedule changes when granting privileges across supported cloud platforms and SaaS applications. Access follows current responsibility rather than yesterday’s spreadsheet.
That improves both provisioning and deprovisioning. The right access arrives when needed, while unnecessary access is removed without depending on someone remembering to clean it up later.
Rootly context makes access reviews more useful
Traditional access reviews often show that a user possessed a role but provide little explanation of why.
Rootly context helps answer the more useful question: Was this access appropriate at that particular time?
Trustle administrators can review privileges alongside identity status and relevant provisioning or deprovisioning events. That creates a clearer record connecting operational responsibility with access.
Instead of merely proving that a responder had production privileges, we can demonstrate that they were scheduled for incident duties when those privileges were granted, and that the access was removed afterward.
That’s stronger evidence for security reviews, investigations, and audits. It also reduces identity risk by making access decisions easier to explain rather than just easier to export.
Rootly handles response; Trustle controls exposure
Incident response requires speed, but speed and security aren’t natural enemies. Poorly connected systems simply make them look that way.
Rootly helps determine who needs to act. Trustle uses that context to control what they can access and for how long.
Together, they replace two bad options, waiting for manual approval or granting permanent production access, with a cleaner model: immediate approval for the person currently responsible, followed by automatic revocation when that responsibility ends.
Because an incident should leave us with restored services and useful lessons. It shouldn’t leave another administrator account lying around indefinitely.
Connect Rootly schedules to automated, time-bound privileges with Trustle. Responders receive the access they need during their shifts, and permissions are automatically removed when that responsibility ends. Start your free Trustle trial and see how just-in-time access can reduce ticket delays, standing production privileges, and manual access cleanup.




