PAM Capability Design · RFP Evidence · v1.0 · June 2026

Privileged Access
Brokering

Managing and brokering privileged access to authorized human users and authorized machines on a temporary basis.

Product ZenXPAM
Status Production capability
Prepared by Zenxsys
Zenxsys
ZenXPAMPAM
Section 1 · RFP Response

RFP Response Summary

Assessment requirement

Managing and brokering privileged access to authorized human users (e.g., system administrators, operators and help desk staff) and authorized machines (e.g., systems, applications, workloads etc.) on a temporary basis.

✓ Capability: Yes - Supported
FieldResponse
CoverageHuman operators and machine/workload identities via JIT, standard, and emergency paths
ApproachRequest → approve → broker (Zenx Gateway) → monitor → auto-revoke with vault injection
AuditRequest, grant, session, command, and revocation events logged tenant-scoped
Suggested RFP comment (≤150 chars)ZenXPAM brokers time-bound privileged access for humans and workloads via JIT grants, Zenx Gateway sessions, vault inject, auto-revoke, and immutable audit.
Section 2 · Problem & Design Goals

Manage · Broker · Expire

Every path enforces time bounds, brokered connections, and revocation - eliminating standing privileged sessions without governance.

GoalDesign Choice
Temporary by defaultJIT max/default/min duration; auto-revoke on timeout
Human authorizationRBAC personas + approval + MFA + policy scope
Machine authorizationNHI registry · workload OAuth · REST vault API
Session brokeringtunneling-service + Zenx Gateway; no password handoff
Ephemeral identitiesJIT Dynamic Identity - provision on grant, deprovision on revoke
Supporting Links (RFP Portal)

Evidence References

#ReferencePath
1Privileged sessions (user guide)docs/guides/user-guide/05-privileged-sessions.md
2Session access guidedocs/guides/SESSION-ACCESS-USER-GUIDE.md
3JIT dynamic identitydocs/guides/JIT-DYNAMIC-IDENTITY-OPERATOR-GUIDE.md
4Access request guidedocs/guides/USER-ACCESS-REQUEST-GUIDE.md
5RBAC & centralized policydocs/implementation/PAM-RBAC-CENTRALIZED-POLICY-DESIGN.md
Zenxsys
ZenXPAMPAM
Sections 3–7 · Principals & Brokering

Humans, Machines & Broker Stack

Privileged access is brokered only to authorized human users and machine identities - never as standing shared passwords on endpoints.

Authorized Human Users

  • System administrators - JIT to servers, DBs, cloud
  • Operators & help desk - short-duration JIT + ticket policy
  • Approvers - scope grants; no standing target privilege
  • RBAC: access.request · access.create · access.approve
  • Help desk cannot self-grant without access.create

Authorized Machines & Workloads

  • Service accounts - vault-backed; rotation schedules
  • Applications & microservices - NHI + linked accounts
  • Workload OAuth · API clients - registry + allowed hosts
  • Cloud IAM - ephemeral JIT console roles
  • REST vault API for machine credential retrieve
Three Temporary Access Paths
StandardCertified Entitlement

Standing access with periodic certification and least-privilege review.

  • Time-window grants with certification cycle
  • Session broker connect - no password handoff
  • Auto-revoke on role change or offboard
  • Permanent privileged accounts (AccessMode=Permanent)
  • Periodic access review evidence
Just-in-Time15 min – 4h default

On-demand elevation with justification, approval, and mandatory expiry.

  • JITAccessPolicy duration caps (min/default/max)
  • JIT Dynamic Identity - ephemeral accounts
  • Workflow auto-revoke template
  • Intent-locked command scope option
  • Enhanced monitoring default on JIT policies
EmergencyBreak-Glass

Expedited incident access with enhanced monitoring and post-review.

  • access.emergency permission required
  • Security notification on grant
  • Immutable audit chain for every action
  • Mandatory post-incident review workflow
  • Isolated /emergency-access route
access-service → tunneling → Zenx Gateway → vault

Zero Credential Exposure

Approved grant → launch session → vault retrieve (service auth) → Zenx Gateway inject → target connect. Password never shown in user UI during normal flows.

RDPDesktop
SSHTerminal
RemoteAppSingle app
BrowserWeb PAM
JumpDMZ path
DBSQL gateway
ComponentRole
access-serviceGrants, expiry, revocation, JIT identity orchestration
tunneling-serviceTunnel lifecycle, protocol injection, thick-client proxy
Zenx GatewayUnified in-browser RDP, SSH, VNC, browser sessions
vault-serviceCredential retrieve at connect - 6 app login resolvers

Session Governance

  • Intent locking - Monitor · Warn · Strict
  • Command rules - block · allow · alert
  • Session recording & spectator mode
  • AI threat scoring during live session
  • File transfer & clipboard monitoring

Auto-Revoke Triggers

  • Grant time window elapsed
  • Session end → JIT identity deprovision
  • Policy workflow revocation rule
  • sessions.terminate by SecurityOperator
  • RevokeOnPolicyViolation on command breach

Machine / NHI Access

  • Service accounts - vault-backed + rotation
  • Workload OAuth clients - registry + allowed hosts
  • REST vault API for authorized machines
  • Cloud IAM - ephemeral JIT console roles
  • Linked privileged accounts per workload

Broker Sequence

  • Approved grant → launch session request
  • vault-service retrieve (service auth only)
  • Zenx Gateway inject - user never sees password
  • Session recorded & audited end-to-end
  • Auto-revoke on expiry or session end

Temporary by design. Every path enforces time bounds, brokered connections, and revocation - eliminating standing privileged sessions without governance.

Zenxsys
ZenXPAMPAM
Sections 8–14 · UI, API & Validation

Surface Map, JIT Defaults & PoC

TaskNavigationPermission
Request JIT accessAccess → JIT Accessaccess.create
Request standard accessAccess Requestsaccess.request
Approve temporary grantApprovals inboxaccess.approve
Connect (brokered)My Access → ConnectActive grant required
Active sessionsOperations → Sessionssessions.read
Workload vault APIREST / integrationvault.read (machine)
MethodEndpointPurpose
POST/api/v1/access/requestsSubmit access request
POST/api/v1/access/requests/{id}/approveApprove time-bound grant
POST/api/v1/tunneling/sessionsStart brokered session
POST/api/v1/access/grants/{id}/revokeRevoke temporary access
GET/api/v1/access/jit-identity/settingsJIT dynamic identity config
JIT SettingDefault
MaxDuration240 minutes (configurable per policy)
DefaultDuration60 minutes
MinDuration15 minutes
ApprovalRequiredtrue · JustificationRequired: true
Sections 11–14 · Security & Acceptance

Controls & Evaluator Checklist

ControlImplementation
Authorized users onlyRBAC + policy principal matchers
Authorized machines onlyNHI registry + resource/account linkage
Temporary basisJIT duration caps; auto-revoke; no indefinite standing JIT
Brokered connectZenx Gateway + vault inject; user never sees target password
ComplianceSOC 2 · ISO 27001 · PCI-DSS · HIPAA session evidence
Evaluator PoC Checklist
  • Submit JIT request as operator; approver grants 1-hour window
  • Connect via brokered session; confirm password not shown to user
  • Verify session in Active Sessions with correct user and resource
  • Wait for grant expiry; confirm reconnect denied without new approval
  • Enable JIT Dynamic Identity; verify ephemeral account created and removed
  • Retrieve workload credential via REST vault API for authorized machine
  • Terminate session as SecurityOperator; audit shows terminate event
  • Export audit chain: request → approve → connect → revoke
  • Confirm help-desk user without access.create cannot self-grant JIT
Version 1.0Date June 2026Author Zenxsys