For every control somebody can bypass

Override & Break-Glass Register

Somebody broke the glass last quarter. Find out whether your systems know who — or only which account.

Accountability attaches at the moment of use, or not at all. A perfect audit log of a shared account is a perfect record of nobody, however carefully everything else was recorded.

instant download · .xlsx · yours to keep

The problem

The log is immaculate. It names an account.

The deployment freeze was overridden in March. The record shows the reason, the control that was bypassed, the timestamp, and a review signature. It also shows the credential — one four people hold, because that is how the runbook was written when there were two of them. Somebody made that call and the system does not know which somebody, and no amount of additional logging will ever recover it.

2
dispositives

A shared credential, or an override that never ends. Either one decides the row on its own, whatever else is recorded.

1
field between top and bottom

Two paths in the worked example are identical on every observation except who the system knows broke the glass. One reads ACCOUNTABLE. One reads UNATTRIBUTABLE.

0
credit for an empty register

Controls with no override path are listed and not graded. A control nobody can bypass is one people improvise around, and that is recorded nowhere.

What's inside

One spreadsheet, six answers per control.

The two that decide on their own
  • Who does the system know broke the glass, at the moment it happened?
  • How does the override end — on its own, when somebody closes it, or never?
The three that lift it to the top
  • Is the reason required before proceeding, typed in afterwards, or never recorded?
  • Does the record name the specific control that was bypassed?
  • Does somebody read every use, some of them, or none?

The standard

A name, at the moment of use.

A shared credential is dispositive

The record names an account, not a person, and no amount of logging quality recovers a name that was never captured. This decides the row on its own, whatever else is true of it.

An override that never ends is not one

It is a permanent change to the control, made once and never revisited. There is no discrete event to attach a name to, so it reads at the bottom alongside the anonymous ones.

An empty register is not a pass

Controls with no break-glass path are listed and deliberately not graded. A control nobody can override is one people improvise around, and those improvisations are recorded nowhere at all.

How it works

Two dispositives, then all five or nothing.

Two answers decide a row on their own: a credential more than one person holds, and an override that never ends. Either sends it to the bottom regardless of everything else. Past those, ACCOUNTABLE requires all five — a named person, an override that self-closes, the reason required before proceeding, the bypassed control named, and somebody reading every use. Any shortfall reads LOGGED ONLY, which is a description rather than a failing grade: you know who did it, and you have a log entry rather than an authorisation.

What you'll see

Change who the system knows, and watch the rest stop mattering.

Load a path
Refund ceiling
Does a break-glass path exist for this control at all?
Who does the system know broke the glass, at the moment it happened?dispositive
How does the override end?dispositive
When is the reason recorded?
Does the record show what was bypassed?
Who reads the uses?
This path
ACCOUNTABLE
decided by: -

A named person broke the glass, said why first, the record shows what was bypassed, somebody reads every use, and it closes on its own.

The shipped seven-control example
SOMETHING HERE IS UNATTRIBUTABLE
ACCOUNTABLE 1 of 6 graded
LOGGED ONLY 2 of 6 graded
UNATTRIBUTABLE 3 of 6 graded
no break-glass path: B-07
fix first: B-03
An empty register is not a pass

A control nobody can override is not a safer control. It is one people improvise around, and those improvisations are recorded nowhere at all. Paths that do not exist are listed here and deliberately not graded.

263 uses last year across every path. The busiest path in the example is unattributable and the one used once a year reads better — usage orders nothing.

This is the live engine. The full .xlsx, with every break-glass path you have Both dispositives worked out per row, with the reason named A register that lists the controls with no override path at all

Get the kit — $59

Who it's for

For the control somebody quietly stepped around.

Buy it if
  • Controls in your business can be bypassed, and you could not say by whom, specifically.
  • Some of your break-glass paths run through service accounts or shared credentials.
  • You suspect one or two overrides were opened months ago and never closed.
  • Somebody will eventually ask who authorised a bypass, and you would rather know now.
Not for
  • Deciding who should be allowed to break the glass. It never touches that.
  • Judging whether a particular override was justified. It never looks at that either.
  • Credential hygiene in general. This asks one narrow question about one moment.

Scope: an engineering instrument. It grades a break-glass path, never a person, asserts no regulatory position, and is not legal advice.

Common questions

Direct answers, before you buy.

Check who the log names. If the override is reached with a service account, a team password or a role several people hold, the record names an account rather than a person — and a perfect audit log of a shared account is a perfect record of nobody. This is dispositive: it does not matter how good the rest of the row is. In the worked example one path has the reason required up front, the bypassed control named, every use read by somebody, and it still reads UNATTRIBUTABLE for exactly this reason.

Get it

An hour with your own register.

  • One .xlsx, three tabs, live formulas, worked example pre-filled.
  • Both dispositives worked out per row, with the reason named.
  • Offline. No install, no login, nothing to connect.

← Browse all Quick Kits

Sold by RedHub AI LLC · Secured by Stripe · redhub.ai