[10.3.0 ~] WAC JIT Permissions Acquisition Guide
This guide explains how to acquire Just-in-Time (JIT) permissions for Web Apps via QueryPie WAC. JIT permission acquisition follows this sequence:
Register a Web App in QueryPie WAC.
Register Owners and Members for the Web App.
The user requests access to the Web App they wish to connect to.
The approver, registered as an Owner, approves the user's Web App access request.
Notification
This JIT Permission Acquisition Guide is based on version 10.3.0
.
To follow this guide, you need either Owner or Web App Admin privileges among QueryPie administrator permissions.
Admin-side
1. Registering a Web App
Navigate to the Admin > Web Apps > Connection Management > Web Apps menu.
Click the
Create a Web App
button to go to the web app registration page.

Enter the following information:
Name : QueryPie Web Site
Base URL :
querypie.com
or10.10.10.10:443
Sub-paths (e.g., /ko) cannot be included in the Base URL.
An error message is displayed if
https://
is entered in the Base URL.An error message is displayed if
www.
is entered in the Base URL.
Description: Enter a description for the web app (e.g., QueryPie Website).
URL Paths: Enter sub-paths. Leave this blank for now.
Watermark: Select whether to apply a watermark to the user's browser screen when accessing the web app.
This helps prevent screen leakage by displaying information such as the accessor and access date/time on the browser when the web app is accessed.
This guide will assume it is set to On.
User Activity Recording: Whether to record user activity.
Set to On and enable all options.
Excluded URL Paths is for entering paths to exclude from user activity recording. Leave this blank for now.
Tag: Tags for the web app. Leave this blank for now.
Click the
Save
button to save.
2. Registering Web App Owner / Member

Access the web app's details page.
Click the Owner/Member button in the upper right corner.
A drawer will open on the right. Search for the target user and assign them a role by selecting the Owner (left) or Member (right) button in the "Assign as" column.
There are two roles for Just-in-Time (JIT) permission grants:
Owner: An entity that can approve Just-in-Time requests for this web app.
Member: An entity that can submit Just-in-Time requests for this web app.
3. User Requesting JIT Web App Access Permission
To access Web Apps via QueryPie, installation of the Root CA certificate and the Chrome Extension is required.
For installation instructions, please refer to the following sections in the 10.3.0-en WAC Quickstart guide:
WAC Quickstart | 1.-Root-CA-인증서-설치하기

After logging into QueryPie, click Web Apps at the top.
Click Role on the left and select “Just In Time Role”.
Click the Web App you want to access.
Click “Request Access” in the alert that appears to go to Workflow.

Access the Web App Just-In-Time Access Request page.
Complete Step 1. If you clicked on an item assigned to you in Web Apps, no separate selection is needed.
Web App: Only items for which the user is designated as a Member can be selected.
Approvers: Displays Users designated as Owner.
Complete Step 2.
Request Title: Enter the request title.
Access Duration (Minutes): Enter the duration of use. Requests are made in minute increments.
Reason for Request: Enter the reason for the request.
Click Submit.
The following restrictions apply when requesting JIT (Just-in-Time) permissions:
The approver is fixed as the Web App Owner.
The approval condition is fixed so that approval is complete if at least one of multiple approvers approves.
Adding approval steps or changing approvers is restricted.
Post-approval mode appears if enabled in Approval Configuration; if set to Off, it will not appear on the request screen.
4. Approver Approving the JIT Web App Access Permission Request

The user with approval authority (designated as a Web App Owner) accesses Workflow.
Navigate to the Received Requests > To Do menu.
Click the request to go to its Detail page.
Click Approve at the top.
5. Accessing the Web App via QueryPie

Go to QueryPie Web Apps.
Click Role in the upper left corner and change it to Just In Time Role.
In the Web App Dashboard under My Apps, the QueryPie Web Site app icon you requested earlier will show “JIT Active”. Click the icon to access the website.
When the requested time expires, access permission is automatically revoked.