Identity before the host sign-on

Give each browser user the right IBM i doorway.

PristineScreen400 separates the person entering the application from the IBM i identity that opens the host session. Administrators grant exact profiles, users see only their assignments, and protected IBM i credentials remain behind the browser boundary.

Direct answer

What makes IBM i access managed?

The browser never chooses a host, port, TLS setting, IBM i user name, or password. It submits an assigned grant identifier. The server resolves the corresponding protected credential, validates policy, and opens the live workspace for the authenticated owner.

Access sequence

One visible choice, several enforced controls.

The application account and IBM i profile serve different purposes. Keeping them separate lets administrators change browser access without modifying the host application.

01 AUTHENTICATE

Sign in to PristineScreen400

The user authenticates with a dedicated application account and receives an opaque, server-validated session.

02 RESOLVE

Select an assigned grant

The browser displays only enabled IBM i identities explicitly granted to that application user.

03 CONNECT

Open the host session

The server decrypts the selected credential for connection use and signs on through the configured TLS-only IBM i target.

Visible administration

Inspect the effective access, not just a preset name.

Application users, IBM i identities, and exact grants remain distinct administrative records.
USERS

Application accounts

Create, disable, reset, and assign user or administrator roles without exposing stored password values.

IDENTITIES

Protected IBM i profiles

Rotate or disable IBM i credentials through administration. Existing values are never redisplayed.

POLICY

Grant-specific capability scope

Assign panels, capabilities, risk ceilings, approvals, and resource allow-lists to the exact user and IBM i grant.

Frequently asked questions

Access controls to confirm

Do users enter their IBM i password in the browser?

No. An administrator stores and rotates the IBM i credential. The server resolves it only for an authorized connection, and it is not returned through browser APIs.

Can one application user receive more than one IBM i profile?

Yes. Administrators can assign enabled IBM i identities to individual application users. The user chooses only among active grants assigned to that account.

What happens after a grant is revoked?

The affected user can no longer select the identity, and active workspaces tied to the revoked access are closed or invalidated.

Plan grants before rollout

Map your users and IBM i profiles before deployment.

A technical access review identifies the required grants, credential rotation process, target boundary, and capability assignments.

Plan an access review