What is PAM?
Privileged Access Management, told as a story about the master key kept in a vault.
The castle has one key that opens every door.The fixers (admins) use it. Steal it, and the whole castle opens.
Master keys end up lying around.Nobody knows how many copies exist. One is in the pocket of someone who quit.
PAM locks the master key in a vault and lends it out.Only when needed, with a reason, for a set time. The ledger says who took it and when.
Watched while in use, reforged when returned.The returned key changes shape the same day. A secret copy is useless.
If it's a hassle, people skip the vault.So there's an emergency key behind glass. The catch: broken glass is always noticed.
PAM = keep the key that opens everything in a vault, lend it only when needed, watch it, and reforge it on return.
Privileged Access Management. Admin, root and service-account passwords are the 'master key'. It's 'one key, for a while' (Zero Trust) applied to the most dangerous key of all.
When grown-ups say it
- Privileged account
- The master key. Admin, root, service accounts. Every door opens.
- Vault
- The vault. Where the key lives when not in use — not in someone's pocket.
- Checkout · Just-in-time
- Borrowing. Take it out with a reason, for a short while. → the castle that always asks
- Session recording
- Watching over the shoulder. The screen is recorded while the key is in use.
- Credential rotation
- Reforging the key. A new password the moment it's returned. Secret copies stop working.
- Audit log
- The key ledger. Who took it, when, why. → also sent to the big screen
- Break-glass
- The key behind glass. The emergency exit when the vault is down. Using it always sets off an alarm.
- Standing privilege
- The key that's always in the pocket. What PAM exists to remove — replaced by borrow-and-return.