Privileged Access Management (PAM) Gaps
The PAM Is Deployed. Customer Environment Access Bypasses It Entirely.
7 min read · 31 May 2026 · Security
A managed services vendor had deployed CyberArk as their privileged access management platform , credential vaulting, session recording, and workflow-based access for their internal administrative accounts. The deployment was comprehensive for internal infrastructure: server administration, network management, and database operations all flowed through CyberArk with full session recording and periodic password rotation. When the vendor's support engineers needed to access customer environments , connecting to customer-managed cloud environments, customer application consoles, and customer databases to perform managed services work , they did so through a separate team-specific remote access tool that had been set up years before the PAM deployment and was never integrated into it. Customer environment access credentials were stored in a shared team password manager rather than the enterprise PAM vault. Sessions were not recorded. Access workflows did not apply. The PAM deployment was genuine and well-implemented for internal infrastructure. For the access that most directly affected customer risk , access to customer environments , the PAM was absent. The vendor confirmed PAM deployment in security assessments. They did not volunteer that customer environment access was excluded from PAM scope.
What are PAM Gaps, Really?
Privileged access management is a set of tools and processes designed to control, monitor, and audit the use of privileged credentials , accounts with elevated access to systems, data, and infrastructure. A PAM deployment consists of several core capabilities: credential vaulting (storing privileged credentials securely rather than in shared password managers or employee memory), session recording (capturing all activity during privileged sessions for audit and investigation), access workflows (requiring approval for privileged access requests), and credential rotation (automatically changing privileged passwords on a defined schedule). When fully implemented across all privileged access paths, these capabilities dramatically reduce the risk from credential compromise, insider misuse, and unauthorized access.
PAM gaps arise from the common reality that PAM deployments are typically implemented in phases , starting with the highest-volume or highest-visibility privileged access and expanding over time. Internal infrastructure administration is usually Phase 1 because it involves the organization's own systems, the IT team manages both the PAM and the target systems, and the implementation is organizationally straightforward. External privileged access , access to customer environments, partner systems, and third-party platforms , is frequently Phase 2 or later, or never reaches full implementation because it requires coordination with external parties and the credential types are often different from internal infrastructure credentials.
The customer environment access exclusion is the most significant PAM gap for managed services and support vendors. These vendors hold privileged credentials to dozens or hundreds of customer environments , arguably the most sensitive privileged access they manage. If that access runs through separate remote access tools, team password managers, or individual engineer credential stores rather than through the enterprise PAM, the most impactful privileged access in the vendor's portfolio receives the least governance. The PAM report shows a mature, controlled privileged access program. The customer environment credentials are in someone's LastPass vault.
- Customer environment credentials outside PAM scope , vendor's access to customer systems managed through separate tools rather than enterprise PAM
- Legacy remote access tools predating PAM deployment , older access channels that were never integrated into the PAM
- Shared password managers for customer credentials , team-level or individual password managers holding privileged credentials that should be in the enterprise vault
- No session recording for customer environment access , external access sessions not captured for audit and investigation
- PAM coverage scope not disclosed , vendor confirms PAM deployment without specifying what access is included or excluded
Why this matters
PAM gaps matter for TPRM because managed services and infrastructure vendors who hold privileged access to customer environments represent some of the most consequential supply chain risk points in the enterprise landscape. The SolarWinds compromise was effective precisely because the attacker gained access to SolarWinds' build pipeline , a privileged access point , and used it to reach customer environments through the trust the customers had placed in SolarWinds' update mechanism. The access paths that vendors use to manage customer environments are the access paths that supply chain attackers target.
The absence of session recording is a specific operational consequence of PAM gaps for vendor-to-customer access. When a security incident is investigated, session recording provides the definitive record of what a privileged user did during a session , which commands were run, which data was accessed, what changes were made. Vendor access to customer environments without session recording leaves a gap in the investigation record that cannot be retrospectively filled. What the vendor's engineer did in the customer environment during the period of concern cannot be determined from available evidence.
For TPRM practitioners, PAM assessment requires going beyond deployment confirmation to coverage scoping , specifically asking whether the PAM covers the vendor's access to customer environments, what credential storage mechanism is used for customer environment credentials, and whether sessions are recorded when vendor staff access customer systems.
Where most teams get this wrong
The most consistent failure is treating PAM deployment confirmation as PAM coverage confirmation. A vendor with a mature CyberArk deployment that excludes customer environment access has a well-governed internal privileged access program and an ungoverned external privileged access program. The confirmation describes the first. The gap describes the second. They are both real simultaneously.
- Treating PAM deployment as PAM coverage confirmation
- Customer environment access scope not assessed , whether vendor-to-customer access is in PAM scope
- Credential storage for customer environments not asked about
- Session recording for external access not confirmed
- PAM scope disclosure not required , accepting deployment confirmation without coverage specification
What good looks like
Mature PAM programs cover all privileged access , internal infrastructure and external customer environment access , through the same vaulting, workflow, and session recording capabilities. Customer environment credentials are in the enterprise vault. Customer access sessions are recorded. Approval workflows apply to customer environment access the same way they apply to internal infrastructure access.
- Customer environment credentials in enterprise PAM vault , same vaulting standards as internal infrastructure credentials
- Session recording for all customer environment access , external access sessions captured with the same completeness as internal sessions
- Access workflows for customer environment access , approval requirements applied to customer system access
- PAM coverage scope documented , explicit documentation of all privileged access categories in and out of PAM scope
- Legacy access tool retirement plan , timeline for integrating or retiring pre-PAM remote access channels
Tooling
Enterprise PAM , CyberArk, BeyondTrust, Delinea
Enterprise PAM platforms provide the credential vaulting and session recording capabilities that should cover customer environment access. BeyondTrust Privileged Remote Access specifically addresses vendor remote access scenarios , providing a session recording and access workflow capability designed for external vendor access to customer environments. For TPRM practitioners, asking whether the vendor uses a PAM platform specifically for customer environment access , not just internal infrastructure , provides the coverage scope question.
Vendor Remote Access Platforms , Bomgar (BeyondTrust), ConnectWise Control, TeamViewer with enterprise governance
Purpose-built vendor remote access platforms provide session recording, access approval, and credential management for external access scenarios. For TPRM practitioners, asking whether customer environment access goes through a governed remote access platform with session recording , rather than direct RDP, SSH, or VPN connections without governance , provides a specific customer access governance question.
Governance challenges
The governance challenge with PAM coverage gaps is the organizational effort required to bring legacy access channels into PAM scope. Customer environment access is often managed by specific operational teams (support, managed services, NOC) who have established workflows that predate the PAM deployment. Integrating their access into the PAM requires changing their operational tools, updating their access procedures, and potentially renegotiating access arrangements with customers. This organizational friction means that customer environment access is frequently a known PAM gap that has been documented for the roadmap but not yet addressed.
- Ask about PAM coverage scope explicitly , what is included and excluded
- Ask specifically whether customer environment access is in PAM scope
- Ask about credential storage for customer environment credentials
- Ask about session recording for customer environment access
- Ask about the roadmap for PAM gap closure if gaps are acknowledged
If you are a small team
Ask your managed services and infrastructure vendors two specific questions about their PAM coverage. First: where are the credentials your engineers use to access our environment stored , in your enterprise PAM vault, in a team password manager, or in individual engineer credential stores? Second: are sessions recorded when your engineers connect to our environment, and if so, are those recordings retained in a format accessible to us for investigation? Those two questions describe the PAM coverage reality for the access that most directly affects customer risk.
- Ask where customer environment credentials are stored , enterprise vault vs team password manager
- Ask whether customer access sessions are recorded and available for investigation
- Ask about PAM scope coverage , internal vs customer environment access
- Ask about legacy access tool retirement plan if customer access is not in PAM scope
What to require
Ask directly:
"Are the credentials your engineers use to access our environment stored in your enterprise PAM vault , and does the same credential vaulting, session recording, and access workflow apply to customer environment access as to your internal infrastructure access?"
"When your engineer connects to our environment, is that session recorded in a format that you and we could review for investigation purposes , and how long are those session recordings retained?"
Expect as evidence
- Customer environment credential storage confirmation , enterprise PAM vault
- Session recording confirmation for customer access with retention period
- PAM coverage scope documentation , internal and external access
- Access workflow confirmation for customer environment access
A vendor who confirms PAM deployment should be asked specifically whether their CyberArk or equivalent PAM governs the credentials used to access customer environments or whether those credentials are managed separately. The PAM is deployed. The question is what it covers.
How to evidence it
- PAM coverage scope documentation for vendor relationships
- Customer environment credential storage confirmation
- Session recording evidence for vendor access sessions
- Access workflow confirmation for customer environment access
Key Takeaway
A PAM deployment governs the privileged access it covers. Customer environment access that runs through a separate remote access tool, a team password manager, or direct engineer credential stores is privileged access that the PAM does not cover , regardless of how mature the PAM deployment is for internal infrastructure. The vendor confirmed PAM. The PAM governs internal access. Customer environment access , the privileged access that directly affects customer risk , is in someone's LastPass vault. Confirming PAM deployment describes a control. Asking what that control covers describes the governance. Both questions are necessary. The second one is the one that reveals the gap.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association