Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
Service accounts, API keys, CI/CD credentials and now AI agents acting on a user’s behalf. Non-human identities outnumber human ones in most estates — and almost none of them are governed by the systems that govern employees.
CyberArk sells the human vault and Secrets Manager as separate products, because an application requesting a credential ten thousand times an hour is not a person checking one out. Three routes below; each answers a different question about who — or what — is signing in.
Some accounts can change or destroy everything. You need to control who uses them, and prove it.
People and services need to sign in. You need to know it's really them.
Someone has access they shouldn't. You need to find it, remove it, and show an auditor.
Events and audits send people here more often than job descriptions do. If one of these is your week, it already names your route.
An RBI or SEBI CSCRF audit asked how privileged access is controlled
Privileged Access Management
Administrators share a root password nobody has rotated in years
Privileged Access Management
A push-fatigue attack got someone to tap approve at midnight
IAM, SSO & MFA
A legacy application still can't do single sign-on
IAM, SSO & MFA
A leaver kept access for three weeks and nobody noticed
Identity Governance
The auditor wants evidence of periodic access reviews
Identity Governance
Nobody confuses the definitions. They confuse the pairs. Four overlaps, and the one question that settles each:
Are you controlling who gets in, or what they can do once inside?
Buy IAM when you needed PAM and every administrator still shares a root password nobody rotates, with no recording when the auditor asks who did what. Buy PAM when you needed IAM and you have a vault for fifty accounts while ten thousand people sign in with a password and a push prompt.
Do you need access granted, or proven?
Buy IAM expecting governance and the auditor asks for evidence of periodic access reviews that your identity provider never ran. Buy governance when the real gap was joiner-mover-leaver and you have a months-long certification programme for a problem that needed an HR trigger.
Is the thing signing in a person, or a process?
Buy a human vault for a machine problem and your pipelines keep credentials in CI/CD variables while the vault holds fifty administrator accounts. Buy a secrets platform expecting session recording and the auditor's question about who used the domain admin account at 2am has no answer at all.
Is the account controlled, or is the entitlement justified?
Buy PAM and the domain admin credential is vaulted and recorded — while nobody has asked in three years whether those fourteen people should still be administrators at all. Buy governance and the certification campaign approves a list of privileged roles it cannot see being used, with the credentials themselves still shared and unrotated. The vault controls the account; the campaign justifies the entitlement, and an auditor asks for both.
Compare any two terms
The vault and broker for accounts that can change or destroy things, with session recording.
The Privileged Access Management boundary section →The machine half — credentials requested by applications, pipelines and containers, unattended.
The Privileged Access Management boundary section →The difference
A vault for humans and a vault for code. PAM brokers a credential a named person checks out, with a session to record and an approval to log. Secrets management serves an application, pipeline or container requesting a credential unattended, thousands of times an hour, with no session and no human. CyberArk sells both as separate products — that is the clearest statement of the difference you will find.
These are adjacent scopes, not tiers. IGA is not IAM done better — it answers a different question, needs different people, and takes far longer to implement than buyers expect. Each route’s guide resolves only the four its buyer confuses.
Service accounts, API consumers, pipeline credentials, workload identities and now AI agents authenticate constantly, unattended, and outnumber human identities in most estates by a wide margin. No manager owns them, no HR event ends them, and no certification campaign reviews them. Every route on this page was designed for people first — ask each vendor what it does for the other population, and expect a thinner answer than the brochure implies.
Microsoft Entra ID P1 (roughly $6–7 per user per month, already inside Microsoft 365 E3) gives SSO and full conditional access; P2 (about $9–10, inside E5) adds Privileged Identity Management. Google’s Cloud Identity Premium is around $6. The useful question is never “which identity provider” but “where does the one on my invoice stop” — usually at legacy protocols, non-Microsoft depth, or governance evidence.
“Supports MFA” covers both a push notification a tired person taps at midnight under a fatigue attack and a FIDO2 security key an attacker cannot phish at all. Push fatigue is a live technique, not a theoretical one. Every guide here records documented FIDO2 and passkey support per product — and marks it unknown where vendor documentation does not establish it, rather than assuming.
The RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (7 November 2023, in force 1 April 2024) requires need-based access and multi-factor authentication for privileged users; SEBI’s CSCRF (August 2024) sets least-privilege and privileged-access requirements; the IRDAI Information and Cyber Security Guidelines, 2023 (24 April 2023) require privileged access management and periodic access reviews. Each names a control and an evidence expectation — not a product category. Read the circular before the brochure.
The licence is the small number. Onboarding, implementation and the population nobody governs are the purchase.
Identity vendors are absorbing privileged access — Okta, One Identity and miniOrange all sell a vault beside the sign-in, and Palo Alto Networks announced its acquisition of CyberArk in July 2025. Endpoint vendors are adding identity threat detection from the other side (CrowdStrike Falcon Identity Protection, SentinelOne Singularity Identity). And ITDR is emerging in the gap between identity and security operations: continuously scoring the session after sign-in, which neither an identity provider nor an endpoint agent was originally built to do. Buying two of these today often means buying one thing twice.
Buy for the seam that is moving, not last year’s org chart — and buy the scope, not the brand.
Almost every buyer in this category already holds part of what they are about to purchase — usually the sign-in half, occasionally the governance half, almost never the machine half.
If the half you need is already on your invoice, we say so. It costs us a sale and saves you one.
Three meters live in this category, and a fourth number under all of them: the project. Which meter you are quoted tells you which route you are in — order of magnitude here, the tier- and term-matched USD + INR number is each guide’s job.
Five vendors span all three routes; every product on the guides is mapped by SKU, not by vendor. SailPoint, Saviynt, Ping Identity, Delinea and JumpCloud are named in the guides where relevant but have no TechBag intel pages yet, so they are not ranked. Microsoft appears in the index and in every “already own” section, but its identity SKUs are not carded on the guides.
Know your route and want it narrowed to a shortlist? That’s the next page’s job — or ours.
Talk to an advisorVendor-neutral · no gated content