Just-in-time (JIT) access is access granted only when needed and normally for a limited duration. It may be requested by a user, triggered by a workflow or created automatically after policy and risk checks.
JIT reduces standing privilege, but it still requires eligibility rules, approval where appropriate, strong authentication, time-bounded enforcement, logging and automatic revocation.