Skip to content
Adaptive package · Least-privilege operations

Foyer: the least-privilege action console

Every shared admin password is a standing risk: anyone who holds it can do anything, and the logs cannot tell you who did what. Foyer is a guardrailed operations console. Your staff run specific approved actions - DNS changes, releasing stuck file locks, password resets, vulnerability remediation - on your systems, without shared admin credentials and without root.

No shared admin creds Every action logged Runs in your environment

What Foyer does

Foyer is a least-privilege action console for IT operations. Instead of handing a technician full root or domain admin, you grant a web console that runs only the operations you have approved, against only the systems you have allowed, with every action logged. The console holds the privilege. Your people hold buttons.

Scoped actions instead of admin rights

  • Operators run named actions, not shells: no terminal, no root session, no standing admin login
  • Each action is scoped to specific targets, like a DNS zone, a file share, or an OU
  • Role-based permissions decide which operator can run which action against which system

Prebuilt operations that cover real tickets

  • Self-service DNS record changes, without anyone touching the DNS server itself
  • Finding and releasing stuck file locks on network shares, the classic "someone left the file open" ticket
  • Account password resets, limited to the accounts you allow
  • A vulnerability board where staff self-assign findings, with owners and remediation target dates

Audit that writes itself

  • Tamper-evident audit trail: who ran what, against which system, when
  • Every action is attributed to a named person, because there is no shared login to hide behind
  • No shared admin credentials to leak, escrow, or rotate after someone leaves
IT administration workstation with a simple control panel on screen
The console holds the privilege. People hold buttons.

The shared-credential problem

Most IT teams grow into the same pattern. Routine tickets, a DNS change, a locked file, a password reset, each need admin rights somewhere, so admin rights spread. More people end up in Domain Admins than anyone planned. Passwords get shared, written down, and reused. When someone leaves, every credential they touched has to be rotated, and everyone knows which ones were missed. And when something breaks, the log says "administrator" and cannot say who.

Least privilege is the accepted fix: give each person the minimum access their job requires. The hard part is applying it when the tooling assumes admin. Foyer applies it at the action level instead of the account level. Nobody holds the credential. The console holds it, and people hold only the approved actions you have granted them.

How it works

Foyer installs in your environment and runs against your systems, under your control. You approve the action patterns and the targets they may touch. Your staff run those actions from the console, holding no admin rights of their own. The audit trail records the rest.

Secured server room door with keycard reader
Like a foyer: visitors get exactly as far as you allow.

Who it is for

  • IT teams where too many people hold domain admin because that was the only way to close tickets
  • MSP-supported businesses that want to delegate day-to-day operations safely, without handing out the keys
  • Compliance-driven organizations that need to prove who did what, when
  • Helpdesks doing DNS changes, lock releases, and password resets all day

What you can expect

Honest scoping first. We start with the tickets your team actually closes and the systems those tickets touch, then scope the actions and targets to match. No action goes live that you have not approved.

The R&D is already done. The guardrails, the scoping, and the audit plumbing are already built and proven in production. Your engagement configures them for your environment; it does not fund an experiment.

Least privilege from day one. Foyer starts from $295 per month plus a one-time $2,500 onboarding, with perpetual licensing available on request. From the first action, nobody on your staff holds a shared admin credential.

Frequently asked questions

What is a least-privilege action console?

A console that lets staff run specific approved operations against specific allowed systems without holding admin rights themselves. The privilege sits in the console, each operator gets only the actions their role grants, and every action is logged and attributed to a named person. It is the least-privilege principle applied to day-to-day IT operations.

How is this different from a password manager or PAM tool?

A password manager or PAM tool vaults credentials so a human can check them out and use them. Foyer removes the credential from human hands entirely: staff run the approved action, and the console holds the privilege. There is nothing to check out, misuse, or forget to check back in.

What operations are prebuilt?

DNS record changes, finding and releasing stuck file locks on network shares, account password resets, and a vulnerability board where staff self-assign findings with owners and remediation target dates. Each operation is permissioned per operator and per target system.

What does it cost?

Foyer starts from $295 per month plus a one-time $2,500 onboarding fee. Perpetual licensing is available on request. Tell us your environment and the tickets you want to delegate and we will scope it.

Can we add our own actions?

The pattern is approved operations against allowed systems, and scoping a new action to your environment is part of an engagement rather than a self-serve builder. Tell us the ticket you want to delegate and we will scope what it takes to turn it into a guarded, logged action.

Hand out buttons, not root.

Tell us the tickets your team closes every week and we will scope Foyer to run them, with nobody holding a shared admin credential.

Or email: info@adaptiveips.com