How it works
When JIT Viewing is enabled:- Users can open a session and review its metadata, status, user, device, agent, timing, and related security records.
- Sensitive content in Telemetry and Replay remains locked.
- A user selects Request access, provides a justification, and chooses an access duration.
- An assigned owner or a policy manager reviews the request through the Responses workflow.
- Approval creates a temporary grant for that requester and that session only.
- The grant expires automatically and the content becomes locked again.
Enable JIT Viewing
- Open Settings.
- Select Ownership.
- Turn on Require approval for session content.
Route requests to owners
JIT Viewing uses the standard Responses ownership workflow. When the session user is linked to a directory group, Forge looks for an active owner assignment for that group. To route requests to a specific team:- Open Settings.
- Select Ownership.
- Add an owner for the directory group whose requests the team should review.
- Choose Slack channel, Slack direct message, or email notifications as needed. Without a notification method, requests remain available in the Console.
Request access
Open a session with locked content and select Request access from Telemetry or Replay. Every request requires:- A justification.
- A requested duration.
- Approval before content is unlocked.
What remains visible
JIT Viewing locks sensitive content rather than hiding the entire session.
Fields that were never collected or retained remain unavailable after access
is approved.
Grant lifecycle
An approved grant is bound to:- The requesting Console user.
- The selected session.
- The approved expiration time.
Audit trail
Forge records the JIT Viewing lifecycle in the organization Audit Log, including:- Changes to the organization setting.
- The access request, requester, session, and requested duration.
- Approval or rejection through the Responses workflow.
- The temporary grant and expiration.
- Access to unlocked Telemetry or Replay content.
Related pages
Sessions
Review session metadata, Telemetry, and Replay.
Roles
Control who can view telemetry, manage policies, and administer settings.
Ownership
Route temporary access requests to the appropriate people and teams.
Responses
Review assigned and organization-wide governance requests.
Audit Log
Inspect access requests, decisions, grants, and viewed surfaces.