Introduction¶
Auditing break-glass emergency access scenarios is a critical aspect of DSH plugin development and agent operations. We need to verify that a session was properly closed within its declared lifecycle and that only permitted operations were performed. This plugin provides tools for validating this settlement evidence.
What This Is¶
dsh-break-glass-settlement-proof is a DSH plugin maintained by user dongsheng123132. Its core function is to provide offline, deterministic evidence for validating user-supplied break-glass session closure evidence. It does not attest to the authenticity of receipts, nor does it provide access control; it only performs verification.
Core Features¶
The plugin primarily provides the following capabilities:
- Offline Evidence Validation: Provides offline, deterministic evidence for session settlement.
- Lifecycle Checks: Validates session activation, termination, and expiration states.
- Operation Auditing: Checks whether operations within the active interval are on the allowlist.
- Permission Revocation Validation: Validates that all declared permissions were revoked before closure and that the revocation receipt is non-zero.
- Tool Support: Provides DSH-native tools and MCP tools, including
dsh_break_glass_inspect,dsh_break_glass_verify,break_glass_inspect, andbreak_glass_verify. - Security Reports: Generates content-addressed and redacted reports.
Installation and Enablement¶
Installation requires using the DSH plugin command and specifying an absolute path. The command is as follows:
dsh plugin --profile <profile> add /absolute/path/to/dsh-break-glass-settlement-proof
Typical Usage¶
After installation, the plugin’s features can be invoked via CLI or code. According to the documentation, typical usage is as follows:
node bin/dsh-break-glass-settlement-proof.mjs inspect examples/settled.json
node bin/dsh-break-glass-settlement-proof.mjs verify examples/settled.json
Applicable Scenarios and Notes¶
- Applicable Scenarios: Suitable for scenarios that require auditing whether break-glass sessions were closed in a compliant manner, especially security operations and compliance audits.
- Notes:
- This plugin is not an identity provider or privileged access manager; it does not grant, activate, approve, or revoke access.
- It only validates provided settlement data, and does not validate the authenticity of the receipts themselves (i.e., it does not perform identity authentication).
- It does not query live identity infrastructure.
residualGrantCount: 0is only a declaration in the provided closure evidence and is not a factual statement.- Before use, please review the source code and license (MIT).
Conclusion¶
By providing offline, deterministic validation capabilities, this plugin helps developers and administrators quickly verify the settlement status of break-glass sessions without relying on live infrastructure. For more details, please refer to the GitHub repository.