{"wiki":{"id":2967,"slug":"tyr-jit-broker-01","entity_type":"droid","entity_id":"tyr-jit-broker-01","title":"JIT Access Broker","prose_md":"## About\n\nThe JIT Access Broker is a small, on-demand droid owned by [[agt_039]] that handles just-in-time access requests: it takes a request, runs an approval step, and mints short-lived, time-boxed grants through the access app's `/api/jit` endpoint. It exists so agents can get temporary access when they need it, instead of holding permanent permissions — a safer default for a system where access should be the exception, not the norm.\n\nIt works by listening for JIT requests, checking them against approval rules in [[agent-access]], and issuing grants that expire after a set time. Because it is on-demand with no fixed schedule, it only runs when someone actually asks for access, and its duties and constraints are not formally recorded.\n\nThe droid's name \"JIT Access Broker\" is unique, and it is not part of a named droid family — its family is recorded as (none), a category shared by 222 droids across many owners, but this particular droid is a one-off. Its execution engine isn't recorded yet, so it isn't known whether it is pure software or calls Claude; no source has been located to confirm either way.","namesake_json":"{\"engine\": \"unknown\", \"model\": null, \"claude_purpose\": null, \"family\": \"(none)\", \"family_size\": 222, \"is_unique\": true}","profile_pic_path":"","source_hash":"765b31edd580f44695d2885e4ea3b35f78869beb4de16fa49671507389a5ac18","status":"being_built","last_generated_at":"2026-08-05 02:46:03","created_at":"2026-08-05 02:46:03","updated_at":"2026-08-05 02:46:03"},"facts":{"id":"tyr-jit-broker-01","name":"JIT Access Broker","machine_name":"","owner":"agt_039","function":"Take JIT requests, run approval, mint time-boxed grants (live via the access app /api/jit)","process_type":"on_demand","schedule":"","process_name":"tyr_jit_broker_01","avatar_color":"#94a3b8","created_for":"CAROL-INI-1912","purpose":"Take JIT requests, run approval, mint time-boxed grants (live via the access app /api/jit)","duties":"","constraints":"","status":"running","gender":"","archetype":"","building_block":"sec_identity_access","service_override":null,"enabled":1,"task_key":"security.access_lifecycle","model_free":0},"page":{"type":"droid","page_class":"main","class_label":"Main page","kind_label":"Droid","kind_gloss":"","listed":true}}