PAM Capability Design · RFP Evidence · v1.0 · June 2026

Account Discovery
& Onboarding

Privileged account discovery and onboarding across systems, applications, and cloud infrastructure providers.

Product ZenXPAM
Status Production capability
Prepared by Zenxsys
Zenxsys
ZenXPAMPAM
Section 1 · RFP Response

RFP Response Summary

Assessment requirement

Account discovery and onboarding of privileged accounts across multiple systems, applications and cloud infrastructure providers.

✓ Capability: Yes - Supported
FieldResponse
CoverageOn-premises infrastructure, directory identities, applications, databases, hybrid/multi-cloud targets
ApproachMulti-channel discovery with operator-gated onboarding into vault-backed privileged accounts
AuditEvery scan, sync, provision, and onboard action is tenant-scoped and written to the audit trail
Suggested RFP comment (≤150 chars)ZenXPAM discovers hosts via network scan, collects local accounts via SSH/WinRM/agent, syncs AD/LDAP users, and onboards vaulted privileged accounts with full audit.
Section 2 · Problem & Design Goals

Why Discovery Matters

Enterprise PAM fails when operators cannot identify ungoverned privileged accounts or onboard them safely. ZenXPAM delivers discovery → review → onboard under one console and one audit chain.

QuestionZenXPAM Answer
What accounts exist?Network scan, host inventory, AD/LDAP sync, NHI suggestions
Which are ungoverned?Staged discovery results vs vault-linked inventory
How to onboard safely?Operator-gated provision; vault-first; no silent mass vaulting
Tenant isolation?All discovery rows and provisioning scoped per tenant
Supporting Links (RFP Portal)

Evidence References

#ReferencePath
1Resource discovery guidedocs/guides/RESOURCE-DISCOVERY-GUIDE.md
2Resources & discovery (user guide)docs/guides/user-guide/06-resources-and-discovery.md
3UI resource discoverydocs/guides/UI-RESOURCE-DISCOVERY.md
4Discovery scan agentdocs/guides/discovery-scan-agent.md
5NHI enterprise readinessdocs/guides/NHI-ENTERPRISE-READINESS.md
Zenxsys
ZenXPAMPAM
Sections 3–5 · Architecture

Discovery Channels & Onboarding Pipeline

Five discovery paths feed a single staging and review layer before vault-backed onboarding and post-onboard governance.

NetworkSubnet · CIDR · IP scan
InventorySSH · WinRM · agent
DirectoryAD · LDAP sync
ManualAPI · UI register
NHIOAuth · workload secrets
1 · ScanSubnet sweep, host inventory, directory sync
›
2 · StageResults held for operator review - no auto-vault
›
3 · ProvisionResource + account created; secret in vault
›
4 · GovernPolicy assign · rotation · session inject · audit
DiscoverScan & Sync

resource-service + discovery-scan-agent. UI: Resources → Discovery.

  • Subnet/CIDR ping sweep · explicit IP list
  • SSH/WinRM host inventory (users, groups, services)
  • AD/LDAP user & group sync via identity-service
  • Workload OAuth discovery suggestions (NHI)
  • AI-suggested platform mapping on scan results
ReviewOperator Gated

Scans never auto-create vaulted resources. Human selects candidates.

  • Bulk select · filter · platform assignment
  • Duplicate resources skipped on provision
  • Staged vs vault-linked inventory comparison
  • Per-tenant isolation on all discovery rows
  • Audit entry for every review action
OnboardVault-Backed

AES-256-CBC vault storage; credentials injected only at session connect.

  • Auto-provision resources from scan results
  • PAM onboard: platform user + resource account
  • Server-generated passwords - never emailed to user
  • Optional post-provision rotation schedule
  • Directory path: sync → select → link → vault

Infrastructure Discovery

  • Subnet/CIDR ping sweep - production ready
  • Central scan-agent inventory - production ready
  • SSH/WinRM local account enumeration
  • SNMP native collector - roadmap
  • UI: Resources → Discovery

Directory Discovery

  • POST …/identity-providers/{id}/sync/users
  • POST …/sync/groups
  • GET …/discovered/users · for-resource/{id}
  • PAM-onboard directory user with resource account
  • Identity Providers → Discovery UI

Applications & Cloud

  • Windows/Linux · SQL · web apps · Kubernetes
  • AWS/Azure/GCP via registered console resources
  • Cloud IAM org sweep - roadmap
  • Manual registration fallback always available
  • Hybrid/multi-cloud target support

Design Goals & Audit

  • Least-privilege onboarding - no silent vaulting
  • Tenant isolation on all discovery data
  • Session inject at connect - not at discovery
  • Operator selects candidates before vaulting
  • Scan · sync · provision events in audit trail

Multi-channel, operator-gated. Discovery finds candidates across network, directory, and cloud paths; humans approve before any credential enters the vault - eliminating blind mass onboarding.

Zenxsys
ZenXPAMPAM
Sections 6–8 · Workflows & API

Onboarding Paths & API Surface

Host → Resource → Account

Network Discovery Workflow

Operator starts scan → reviews staged results → auto-provisions selected hosts as managed resources → provisions local privileged accounts → vault stores the secret encrypted with AES-256-CBC → audit logs every step. Directory path: sync AD/LDAP users → operator selects candidates → create/link platform user → optional resource account → assign access policy.

PathUISteps
Host discoveryResources → DiscoveryScan → select hosts → auto-provision → provision account → vault
Directory PAM onboardIdentity Providers → DiscoverySync users → select → create/link platform user → optional resource account
Manual fallbackResources → All ResourcesAdd resource → link account → vault secret → assign policy
MethodEndpointPurpose
POST/api/v1/resources/discovery/scanStart discovery scan
POST/api/v1/resources/discovery/auto-provisionCreate resources from results
POST/api/v1/identity-providers/{id}/sync/usersDirectory user sync
POST…/discovered/users/{id}/provision-accountProvision resource account
GET/api/v1/workload-oauth-clients/discovery-suggestionsNHI suggestions
Sections 9–12 · Security & Validation

Controls, Roadmap & PoC Checklist

ControlImplementation
Operator gatingNo automatic vaulting of all discovered accounts
Tenant scopingDiscovery rows isolated per tenant
Secret handlingServer-generated passwords; vault storage; inject at session
Audit trailScan, sync, provision, onboard/offboard events logged
ComplianceSOC 2 · ISO 27001 · HIPAA · PCI-DSS inventory evidence
AreaTodayPlanned
Scheduled discoveryPartial schedulerFull auto-discovery
Cloud IAM enumerationManual/JIT registrationNative AWS/Azure/GCP sweep
SNMP devicesNot supportedNetwork device collector
Evaluator PoC Checklist
  • Run network scan; results show live hosts
  • Collect host inventory via SSH or WinRM
  • Auto-provision discovered host as managed resource
  • Provision privileged account; confirm vault secret
  • Sync AD/LDAP users; staged users appear in Discovery UI
  • PAM-onboard directory user with optional resource account
  • Launch session without exposing password to user
  • Retrieve audit events for scan, sync, and provision
  • Confirm tenant isolation between tenants
Version 1.0Date June 2026Author Zenxsys