Yeah I don't think a lot of people understand the lengths some companies go to, to control access to their systems (either because of risk aversion, regulatory requirements, or something else). It's on a different planet from a startup mentality of 'We hire trustworthy people, so all 10 employees have access to prod'. This is 'How do we protect customer data from 1 in 2000 IT staff across 100 countries?'
For example, I was working at a massive bank that was implementing an access control system for their servers that meant that admin's didn't have direct access. You had to
- submit a change ticket that went through all the approvals.
- This triggered a workflow through a web interface that opened an RDP or text terminal session to the server, for the appropriate person (OS, application, database, etc)
- The RDP session was recorded to video, the text session was logged.
- Once you logged out the password on the server was auto-rotated.
- The text-session was indexed and searchable. The software coordinating all this was able to match server logs against the video RDP session so you could search through the video ("show me the SQL Server commands that admin ran")
- On a regular basis, the server state would be reconciled against all the logged tickets for that server and discrepancies investigated.