Skip to content
MisterShell

Privileged remote access, under policy.

Control who can reach which resources — servers, network, cloud, Kubernetes, and databases — from where and under which rules, with firewall-style session policy, per-command ACLs, a human approval before access where you require one, encrypted credentials, and full audit with replay. Outbound-only workers fit your segmentation; external vendors join by invitation.

Session policy Access approvals Encrypted credentials No inbound firewall rules Audit & replay
What a large-scale deployment looks like
A role scoped to specific locations, so access follows the org tree
A role scoped to locations — access follows your org tree, not a flat list
The challenge

Privileged access is where risk concentrates

Standing access is hard to bound

Broad credentials and flat network reach mean any account can do too much. Least privilege is easy to say and hard to enforce per resource and per command.

Vendors and contractors need a way in

External parties often get VPN accounts or shared logins — access that is hard to scope, time-box, and attribute when something goes wrong.

Evidence is scattered

Auditors want to know who did what, where, and whether it was allowed. Assembling that from jump-host logs and ticket trails is slow and incomplete.

Inbound firewall holes

Traditional bastions need inbound rules into protected zones — exactly what segmentation policy is trying to prevent.

The approach

Governed sessions, enforced at connection and at every command

MisterShell evaluates firewall-style session policy when a session opens — and in shell sessions, on every command typed, checked at the worker so a denied command never reaches the target. Where a resource warrants it, a rule requires a human approval first, with a grant that expires on its own. Credentials are vaulted and masked, workers connect outbound only, and sessions are recorded and replayable under Recording Policy. Access maps to your directory and roles, scoped per location, and external guests join a single shared session by one-time email invitation without an account.

Session policy rule list
Firewall-style rules, evaluated in order — first match decides, down to a default deny.
Command denied by session policy in a live session
A denied command never reaches the target — blocked live, with the matching rule named.
Command ACL editor with built-in and custom allow/deny sets
Reusable command ACLs — built-in database read-only and mutating-SQL sets, plus the sets you define.
Credential vault with shared and per-user credential mapping
Vaulted credentials — shared or per-user, kept out of command arguments and masked.
Session replay player
Session replay for incident review and audit evidence.
Invite External Participants dialog with one-time join links and pending/redeemed tracking
Invite an external vendor by email — one-time join links with pending/redeemed tracking. No account required.
What you get

Control, isolation, and evidence in one platform

Every session type, one policy

The same governance covers every way in — browser SSH and cloud CLIs, interactive RDP and VNC desktops, Kubernetes and database shells, and proxied web apps. One session policy and one audit trail, whatever the target — checked at connection time everywhere, and command by command in shell sessions.

Session policy & command ACLs

Allow/deny rules — with notify and log flags — by location, resource type, tag, role, or session type, evaluated at connection time and per command in shell sessions. The command check is not naive pattern matching: a command line is taken apart and every part of it has to be allowed on its own, so a blocked command chained onto a permitted one still does not run. Backed by reusable named ACLs: built-in database read-only and mutating-SQL sets, plus the sets you define.

Approval before access

A policy rule can require a human decision before a session opens or a file transfer starts. The roles you name approve, the access expires on its own, and every request and decision is kept as evidence — even after the rule changes (Enterprise edition).

Encrypted credentials

Shared or per-user credential mapping, plus a personal and team vault for each person's own logins with history and audit. Stored credentials are kept out of command arguments and masked in API responses.

Files under the same policy as sessions

Data leaving or landing on a privileged system is governed like any other privileged act. People work against a file catalog carried by your location tree, never the resource directly, and an ordered File Transfer Policy rules on every copy — by location, resource type, tag, role, direction, and both source and destination paths, so a firmware image can be permitted while sensitive destinations on the box stay closed. The whole selection is checked before anything moves, an unmatched transfer is denied, a transfer can require approval too, and each one becomes its own session in the audit trail with operations and hashes recorded — never file content.

Identity & location-scoped RBAC

LDAP, OIDC, and SAML single sign-on (Pro edition), with directory groups mapped to roles and permissions scoped per location — least privilege by default.

No inbound firewall rules

Workers deploy as managed jump hosts inside protected zones and connect outbound only, so MisterShell fits enterprise segmentation instead of fighting it.

External access by invitation

Invite a vendor or contractor to a single shared session by email — a one-time join link, no account, reached over the Session Proxy add-on. Guest access stays off until an admin enables it, session policy still applies, and you can revoke or remove them at any time.

Audit & replay

Policy decisions logged rule by rule wherever a rule enables logging, command timelines on recorded sessions, session recording/replay by policy, and every access request and decision kept as evidence — with security events exported to your SIEM via syslog/CEF (Pro edition), every privileged action is attributable and reviewable.

Get in Touch

Want a guided demo, or a trial license to evaluate Pro or Enterprise on your own infrastructure? Tell us — we'd love to hear from you.