Built for engineering teams

Centralize SSH onboarding and offboarding

Give engineers the server access they need without turning onboarding into an admin project—or distributing persistent user keys to managed servers.

Flotte complements your existing identity and people processes rather than replacing them.

Minutes, not tickets

A repeatable path to SSH access

Your process

Permissions shaped around your team

Short-lived access

Identity-linked SSH certificates

The admin tax

Every new hire triggers a custom access scavenger hunt

Someone remembers which servers exist. Someone else finds the right key. A founder approves access in chat. Months later, nobody is sure what the engineer can still reach.

That process feels flexible at five people. At twenty, it creates repetitive admin work and invisible security debt.

offboarding-checklist.md
Disable company account
Remove GitHub access
Find every production server
Locate copied SSH keys
Ask who granted staging access
Rotate all passwords of all servers
Prove no credentials remain

Stop buying more process

Keep the custom workflow. Remove the fragile parts.

Teams do not need another all-in-one employee platform. Flotte is designed to handle one high-risk job well: who can access which servers, and whether they can obtain access right now.

Less checklist chasing

Keep server-access work out of scattered tickets, spreadsheets, chat messages, and tribal knowledge.

A process that fits

Model your infrastructure and permission groups instead of adapting every internal process to a rigid suite.

Focused, not bloated

Solve SSH access lifecycle management without buying a broad platform for dozens of unrelated employee tasks.

Safer by default

Replace open-ended SSH keys with identity-linked, short-lived certificates and explicit permissions.

Faster changes

Grant or remove future access centrally as roles, teams, contractors, and responsibilities change.

A clearer answer

See who is permitted to reach managed servers instead of reconstructing access one machine at a time.

One access lifecycle

From first day to last, without credential archaeology

Use the identity provider and team structure you already have. Flotte adds a clear permission layer for SSH access to managed infrastructure.

  1. 01

    Connect company identity

    Engineers authenticate through your existing OIDC identity provider and its MFA policy.

  2. 02

    Define access your way

    Map people or groups to the servers they need, without forcing your team into a generic HR workflow.

  3. 03

    Onboard without key copying

    Eligible engineers request short-lived SSH certificates instead of distributing permanent public keys.

  4. 04

    Offboard centrally

    Remove a team member's eligibility in one place when their role changes or they leave.

The security model is intentionally boring

Persistent user public keys do not need to be distributed to Flotte-managed servers. Access is linked to identity, scoped by central permissions, and designed to expire automatically.

Coming Soon

Spend less time administering access

Build a lightweight onboarding and offboarding process that stays flexible as your team grows—and does not trade speed for security.