Sign in to PristineScreen400
The user authenticates with a dedicated application account and receives an opaque, server-validated session.

Managed browser access for IBM i applications
Identity before the host sign-on
PristineScreen400 separates the person entering the application from the IBM i identity that opens the host session. Administrators grant exact profiles, users see only their assignments, and protected IBM i credentials remain behind the browser boundary.
Direct answer
The browser never chooses a host, port, TLS setting, IBM i user name, or password. It submits an assigned grant identifier. The server resolves the corresponding protected credential, validates policy, and opens the live workspace for the authenticated owner.
Access sequence
The application account and IBM i profile serve different purposes. Keeping them separate lets administrators change browser access without modifying the host application.
The user authenticates with a dedicated application account and receives an opaque, server-validated session.
The browser displays only enabled IBM i identities explicitly granted to that application user.
The server decrypts the selected credential for connection use and signs on through the configured TLS-only IBM i target.
Visible administration
Create, disable, reset, and assign user or administrator roles without exposing stored password values.
Rotate or disable IBM i credentials through administration. Existing values are never redisplayed.
Assign panels, capabilities, risk ceilings, approvals, and resource allow-lists to the exact user and IBM i grant.
Frequently asked questions
No. An administrator stores and rotates the IBM i credential. The server resolves it only for an authorized connection, and it is not returned through browser APIs.
Yes. Administrators can assign enabled IBM i identities to individual application users. The user chooses only among active grants assigned to that account.
The affected user can no longer select the identity, and active workspaces tied to the revoked access are closed or invalidated.
Plan grants before rollout
A technical access review identifies the required grants, credential rotation process, target boundary, and capability assignments.
Plan an access review