Introduction

Auditing break-glass emergency access scenarios is a critical aspect of DSH plugin development and agent operations. We need to verify that a session was properly closed within its declared lifecycle and that only permitted operations were performed. This plugin provides tools for validating this settlement evidence.

What This Is

dsh-break-glass-settlement-proof is a DSH plugin maintained by user dongsheng123132. Its core function is to provide offline, deterministic evidence for validating user-supplied break-glass session closure evidence. It does not attest to the authenticity of receipts, nor does it provide access control; it only performs verification.

Core Features

The plugin primarily provides the following capabilities:

  1. Offline Evidence Validation: Provides offline, deterministic evidence for session settlement.
  2. Lifecycle Checks: Validates session activation, termination, and expiration states.
  3. Operation Auditing: Checks whether operations within the active interval are on the allowlist.
  4. Permission Revocation Validation: Validates that all declared permissions were revoked before closure and that the revocation receipt is non-zero.
  5. Tool Support: Provides DSH-native tools and MCP tools, including dsh_break_glass_inspect, dsh_break_glass_verify, break_glass_inspect, and break_glass_verify.
  6. Security Reports: Generates content-addressed and redacted reports.

Installation and Enablement

Installation requires using the DSH plugin command and specifying an absolute path. The command is as follows:

dsh plugin --profile <profile> add /absolute/path/to/dsh-break-glass-settlement-proof

Typical Usage

After installation, the plugin’s features can be invoked via CLI or code. According to the documentation, typical usage is as follows:

node bin/dsh-break-glass-settlement-proof.mjs inspect examples/settled.json
node bin/dsh-break-glass-settlement-proof.mjs verify examples/settled.json

Applicable Scenarios and Notes

  • Applicable Scenarios: Suitable for scenarios that require auditing whether break-glass sessions were closed in a compliant manner, especially security operations and compliance audits.
  • Notes:
    • This plugin is not an identity provider or privileged access manager; it does not grant, activate, approve, or revoke access.
    • It only validates provided settlement data, and does not validate the authenticity of the receipts themselves (i.e., it does not perform identity authentication).
    • It does not query live identity infrastructure.
    • residualGrantCount: 0 is only a declaration in the provided closure evidence and is not a factual statement.
    • Before use, please review the source code and license (MIT).

Conclusion

By providing offline, deterministic validation capabilities, this plugin helps developers and administrators quickly verify the settlement status of break-glass sessions without relying on live infrastructure. For more details, please refer to the GitHub repository.