Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
A PAM platform takes the credentials that can change or destroy everything — domain administrators, root, network gear, database owners, cloud consoles, and the service accounts no human ever logs into — out of people’s hands and into a vault that brokers, records and rotates them.
CyberArk sells the human vault and Secrets Manager separately, because an application requesting a credential ten thousand times an hour is not a person checking one out. Most estates buy the first and discover the second two years later.
Already decided — before the demo
Still yours to weigh
A vault, a broker and a recorder. The vault holds the credentials for accounts that can change or destroy your estate, rotating them so nobody memorises one. The broker gives a named person time-limited use of an account without ever showing them the password — ideally just-in-time, so no standing privilege exists between requests. The recorder keeps a replayable record of what was done, which is the part auditors ask for.
The variable nobody prices is the machine half. Service accounts, API keys, pipeline credentials and the tokens AI agents now carry outnumber your administrators many times over, and a vault designed for humans checking credentials out is a poor fit for an application requesting one unattended, constantly. Read the IAM, SSO & MFA guide for who gets in at all, and the identity governance guide for proving the access granted was correct.
The most common mis-purchase
Endpoint privilege management bought as PAM. PEDM removes local administrator rights from laptops and elevates applications — it vaults nothing. If the audit finding was about server, database or network credentials, PEDM does not answer it, and three products on this page are PEDM.
Often confused withIAM, SSO & MFA — who gets in at all, before what they may do →·Identity Governance — proving the access granted was correct →·Endpoint Protection — identity threat detection sits beside the vault →
The three routes of identity and access — and which one is yours →
Four terms sold by the same vendors, often in the same slide. They are adjacent scopes, not tiers — each answers a different question, and buying one for another is the most expensive mistake in this category.
PAM — privileged access management
The umbrella and the vault: store, rotate and broker credentials for accounts that can change or destroy things, record the sessions, prove it to an auditor. Answers: who used the domain admin account at 2am, and what did they do? This is the main purchase, and the one the regulators' language points at.
PIM — privileged identity management
The lifecycle of privileged identities: which accounts are privileged, who is eligible, for how long, with approval and expiry. Microsoft's Entra PIM made the term familiar — eligible rather than permanent roles, activated on request. Overlaps PAM heavily; where PAM vaults the credential, PIM governs the entitlement.
PEDM — privilege elevation and delegation management
No vault at all. An agent on the endpoint removes standing local administrator rights and elevates named applications or commands instead. Answers: how do we take admin away from laptops without breaking the software? A different budget, a different team, and three products on this page.
Secrets management
The machine half: credentials, API keys and certificates requested by applications, pipelines and containers, unattended and at machine speed. No interactive login, no session to record, no human to approve. A vault for people and a vault for code are different products — CyberArk sells both, separately, and that tells you what you need to know.
Seven variables decide this purchase. The instrument tests what documentation establishes (platform coverage, secrets capability, deployment, recording, discovery, agent model, India origin); onboarding time, break-glass and storage are prose because the honest answers come from a project plan, not a datasheet.
Deployment model
On-premises appliance, self-hosted software, or SaaS — decided by regulator expectations as often as by preference. Indian BFSI deployments are still frequently on-prem; ask your compliance team before your architects.
What it can vault
Windows, Unix and Linux, network devices, databases, cloud consoles, Kubernetes, SaaS administrator accounts. Coverage varies enormously and the gap is always the system you cannot replace.
Session recording and playback depth
Full searchable video-grade recording, basic activity capture, or none. The audit asks for playback; the storage bill arrives separately.
Secrets management for applications and CI/CD
The machine-identity cut. Purpose-built brokering for pipelines and containers, credential storage that applications can call, or nothing. Several products here are genuinely thin — marked, never eliminated on.
Just-in-time access vs standing privilege
Whether privilege exists between requests at all. Every vendor here documents just-in-time in some form; how far it extends beyond the flagship platform is the question.
Agent vs agentless architecture
Agentless reaches more legacy targets with less deployment friction; agents give deeper control and offline enforcement. Most serious platforms do both.
Onboarding and discovery
Can it find the privileged accounts nobody told you about? Discovery is the difference between a vault holding fifty accounts and one holding the estate.
Set what is true for you. A product that misses a constraint fades with its reason printed on it; where documentation cannot settle your case it is flagged, never removed. Every chip is reversible.
The machine half
How it must run
What it must vault
How it works
India
Estate size
Onboarding time, break-glass testing and recording storage are in the notes below, not chips — they are project realities, and no datasheet answers them honestly.

per privileged user / year reported — the wide band is the volume curve (small deployments at the top, 1,000+ users near the floor); Self-Hosted and Privilege Cloud are separate SKUs
Large and regulated estates that want the reference vault — the deepest platform coverage, the strongest session controls, and an audit story every regulator already recognises.
The catch: The most expensive licence here and the heaviest to deploy: reported bands run to $12,000 per privileged user per year at small volumes, and the onboarding project is measured in quarters, not weeks. Secrets management for applications is a separate product (Secrets Manager), not this SKU.

per application / per secret-consuming workload on quote; Conjur-derived, built for CI/CD pipelines, containers and application-to-application credentials
Platform and DevOps teams that need the machine half — secrets for pipelines, containers and applications, rotated and brokered without a human in the loop.
The catch: Not a human PAM product: no session recording, no privileged-user workflow. It is the second purchase alongside the vault, and it is priced and deployed as its own project.

per endpoint / year on quote; removes local admin rights on Windows and macOS and elevates per application (PEDM), not a credential vault
Estates removing local administrator rights from laptops without breaking the applications that need elevation.
The catch: PEDM, not PAM: it elevates on the endpoint and vaults nothing. Buying it expecting a credential vault for servers and network devices is the most common mis-purchase in this category.

per external vendor / year on quote; biometric-verified access for third parties with no VPN and no agent on their machine
Organisations whose auditors ask who from which supplier touched production, and when — without issuing the supplier a VPN account.
The catch: Third-party access only — your own administrators are the main PAM SKU. Priced per vendor, which is cheap at ten suppliers and not at two hundred.
per managed asset / year on the US GSA public-sector schedule (about $1,355 per named user / year on the same list); commercial pricing is a quote — the per-asset meter is the one to model
Estates that want a full vault with discovery and session management, and prefer paying for the machines they manage rather than the people who log in.
The catch: The per-asset meter is cheap for a few administrators over many servers and expensive the other way round; the published figures are a public-sector schedule, not a commercial list. Application secrets are handled, but this is not a CI/CD secrets platform.
per endpoint / year on quote; least privilege and application control for Windows, macOS, Linux and Unix servers (PEDM)
Estates taking local admin away across a mixed Windows, macOS and Unix fleet with application-level rules rather than blanket elevation.
The catch: PEDM again — it removes standing local admin, it does not vault credentials for network devices, databases or cloud consoles. The Unix server coverage is the differentiator against endpoint-only rivals.
per concurrent or named user / year on quote; brokered privileged sessions for insiders and vendors with full recording, no VPN
Teams whose real problem is how administrators and suppliers reach production at all — a brokered, recorded path instead of VPN plus jump box.
The catch: Access brokering with credential injection rather than a full enterprise vault: password rotation depth and discovery live in Password Safe, which is the companion purchase.

per privileged user and per managed target, quoted in INR; Mumbai-built and Mumbai-supported, with reporting shaped for RBI and SEBI CSCRF audits; on-prem is the common BFSI deployment
Indian BFSI and regulated estates that want the vault, the auditor's report format and the support engineer in the same country, time zone and currency.
The catch: Deepest where its market is: platform coverage and the ecosystem of integrations are narrower than CyberArk's, and Kubernetes-native secrets for CI/CD are not its strength. Quote-only, with no public list to anchor a negotiation.

per endpoint, quoted in INR; least privilege, application allow-listing and elevation on Windows endpoints
Indian estates extending least privilege to laptops and desktops from the same vendor that runs their server vault.
The catch: Endpoint elevation only, Windows-centric, and documented scale is smaller than the server-side product's. Not a credential vault.

per user, quoted in INR; a personal and team credential vault for business users — passwords, cards, documents — not privileged infrastructure sessions
Organisations that want employees' shared and personal business credentials in a managed vault rather than a spreadsheet.
The catch: A password manager, not PAM: no session recording, no just-in-time elevation, no discovery of privileged infrastructure accounts. It sits beside the PAM purchase, never instead of it.

priced purely on the number of users — no per-target or per-connector add-ons, which is the whole pitch; quote-based, with a free Password Vault starter for up to five users
Mid-market and lean enterprise teams that want vault, session recording, discovery and remote access in one all-inclusive per-user number instead of six line items.
The catch: No public list price despite the simple meter, and documented deployments are smaller than CyberArk's or BeyondTrust's — flagged rather than ruled out above 1,000 privileged accounts. Application secrets are stored and served, but this is not a CI/CD-native secrets platform.

per endpoint on quote; removes local admin rights and elevates named applications on Windows and macOS
Teams removing local admin from laptops on the same all-inclusive commercial model as the Securden vault.
The catch: Endpoint elevation only; no infrastructure vault. Documented scale is mid-market.

per user or per asset on quote; a hardened appliance heritage with session analytics, and the tightest coupling to Identity Manager for governance-plus-PAM estates
Estates that want the vault and the governance platform from one vendor, with behavioural session analytics on privileged sessions.
The catch: Sold as an appliance-first platform with a heavier deployment than the SaaS-native options, and quote-only. Its strength is the Identity Manager pairing — standalone, it competes without that advantage.

per user / month on quote; SaaS-delivered session-based privileged access with recording — no appliance to rack
Mid-market teams that want brokered, recorded privileged sessions quickly, without an appliance project.
The catch: Session access rather than a full enterprise vault: no discovery, no application secrets, and documented deployments are smaller. The fuller product is Safeguard.

per user / month inside Okta's Essentials workforce bundle (list) rather than as a standalone vault; ties privileged server and cloud access to the Okta identity you already carry
Okta estates that want just-in-time server and cloud access governed by the same identity, policy and lifecycle as everything else.
The catch: Built for cloud and Linux/Windows server access from an Okta-centric estate: network devices, mainframes and the long tail of legacy targets that classic vaults cover are not its ground. It assumes you are already an Okta customer.

per user / month — miniOrange publishes workforce identity from ₹180 per user per month; PAM is quoted on top and remains the cheapest entry point of the vendors here, in INR, from an India-built vendor
Cost-sensitive Indian estates that want a vault, session recording and web-application privileged access without an enterprise-scale licence or an enterprise-scale project.
The catch: The value option, and priced like one: documented deployments are smaller than the enterprise vaults', deep platform coverage (mainframe, exotic network gear) is thinner, and it is not a CI/CD secrets platform.

per user, quoted in INR; brokered and recorded remote privileged sessions for distributed teams and third parties, without a VPN into the network
Indian estates whose administrators and suppliers work remotely and need a recorded, controlled path into production rather than a VPN account.
The catch: Session brokering rather than a full credential vault — rotation, discovery and the enterprise workflow live in ARCON PAM, which is the companion purchase. Documented scale is smaller than the flagship.
Application and pipeline secretsRules out CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Endpoint Privilege Manager, One Identity Cloud PAM Essentials and ARCON Global Remote Access — no application or pipeline secrets capability; it vaults credentials for people. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), BeyondTrust Password Safe, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, Okta Privileged Access and miniOrange PAM. It flags CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud) — Stores and serves application credentials, but is not a CI/CD-native secrets platform, BeyondTrust Password Safe — Stores and serves application credentials, but is not a CI/CD-native secrets platform, ARCON Privileged Access Management — Stores and serves application credentials, but is not a CI/CD-native secrets platform, Securden Unified PAM — Stores and serves application credentials, but is not a CI/CD-native secrets platform, One Identity Safeguard — Stores and serves application credentials, but is not a CI/CD-native secrets platform, Okta Privileged Access — Stores and serves application credentials, but is not a CI/CD-native secrets platform and miniOrange PAM — Stores and serves application credentials, but is not a CI/CD-native secrets platform — marked on the cards, not removed.
Kubernetes workloadsRules out CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access — Kubernetes-native secrets brokering not documented. That leaves CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur).
On-premises deploymentRules out CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, One Identity Cloud PAM Essentials and Okta Privileged Access — SaaS only; there is no self-hosted deployment. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, miniOrange PAM and ARCON Global Remote Access.
Pure SaaS deliveryRules out CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, miniOrange PAM and ARCON Global Remote Access — the deployment includes a self-hosted or on-premises component you run. That leaves CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, One Identity Cloud PAM Essentials and Okta Privileged Access.
Windows serversRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur) — does not vault Windows servers or domain accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access.
Unix and LinuxRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, ARCON Endpoint Privilege Management, ARCON My Vault and Securden Endpoint Privilege Manager — does not vault Unix / Linux accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access.
Network devicesRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Endpoint Privilege Manager, One Identity Cloud PAM Essentials, Okta Privileged Access and miniOrange PAM — does not vault network device credentials. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard and ARCON Global Remote Access.
DatabasesRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Endpoint Privilege Manager, One Identity Cloud PAM Essentials, Okta Privileged Access and ARCON Global Remote Access — does not vault database accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), BeyondTrust Password Safe, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard and miniOrange PAM.
Cloud consolesRules out CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management, ARCON My Vault and Securden Endpoint Privilege Manager — does not vault cloud console access. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access.
SaaS admin accountsRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, Securden Endpoint Privilege Manager, One Identity Safeguard and ARCON Global Remote Access — does not vault SaaS admin accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), BeyondTrust Password Safe, ARCON My Vault, Securden Unified PAM, One Identity Cloud PAM Essentials, Okta Privileged Access and miniOrange PAM.
Full session recordingRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur) and ARCON My Vault — no session recording; CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management and Securden Endpoint Privilege Manager — basic activity capture, not full session recording with playback. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access.
Account discoveryRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Endpoint Privilege Management, ARCON My Vault, One Identity Cloud PAM Essentials, Okta Privileged Access and ARCON Global Remote Access — no automated discovery of unknown privileged accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), BeyondTrust Password Safe, ARCON Privileged Access Management, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard and miniOrange PAM.
Agentless targetsRules out CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management, Securden Endpoint Privilege Manager and Okta Privileged Access — requires an agent on the managed system. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON My Vault, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, miniOrange PAM and ARCON Global Remote Access.
India-built, INRRules out CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, One Identity Safeguard, One Identity Cloud PAM Essentials and Okta Privileged Access — a global vendor; INR quoting is via the channel, not the vendor's own price list. That leaves ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, miniOrange PAM and ARCON Global Remote Access.
Above 1,000 privileged accountsRules nothing out on published terms. It flags ARCON Endpoint Privilege Management — Unverified above 1,000 privileged accounts, ARCON My Vault — Unverified above 1,000 privileged accounts, Securden Unified PAM — Unverified above 1,000 privileged accounts, Securden Endpoint Privilege Manager — Unverified above 1,000 privileged accounts, One Identity Cloud PAM Essentials — Unverified above 1,000 privileged accounts, miniOrange PAM — Unverified above 1,000 privileged accounts and ARCON Global Remote Access — Unverified above 1,000 privileged accounts — marked on the cards, not removed.
Onboarding is the project, not the productEvery vendor here can vault a Windows administrator account in an afternoon. What separates them is account 1,000: the service account nobody owns, the appliance whose password is in a runbook, the application that breaks when its credential rotates. Discovery (CyberArk, BeyondTrust, ARCON, Securden, One Identity Safeguard, miniOrange) finds the accounts; agreeing who owns each one is a governance conversation with your own teams, and it is where PAM projects stall. TechBag's delivery figures for accounts onboarded per week by platform are [TechBag to confirm].
Secrets management is a different productVaulting a credential a human checks out is not the same as brokering a secret an application requests ten thousand times an hour, unattended, with no interactive login. Only CyberArk Secrets Manager on this page is a purpose-built machine-identity platform; the full vaults (CyberArk PAM, BeyondTrust, ARCON, Securden, One Identity, miniOrange, Okta) store and serve application credentials but are not CI/CD-native — marked partial, flagged, never eliminated. If your pipelines and containers are the gap, price the second product now rather than discovering it in year two.
Break-glass and the day the vault is downEvery deployment needs an emergency path when the vault, the directory or the network is unavailable — sealed credentials, an offline copy, a documented two-person procedure. Every vendor supports one; almost nobody tests it. Put the break-glass rehearsal in the implementation plan, not the runbook.
Session-recording storageFull recording produces video-scale data. Retention is a policy decision with a storage bill attached, and it is not in the licence — see the cost section. Ask for gigabytes per recorded hour and set retention before go-live, not after the first audit.
Under 50 privileged accountsRules nothing out on published terms: Securden, miniOrange, One Identity Cloud PAM Essentials and Okta Privileged Access are sold to small estates; CyberArk and BeyondTrust publish no floor but are enterprise-positioned. Where a small estate should stop at a vault and skip the full platform is delivery judgement: [TechBag to confirm].
Each shortlist names what the first ninety days look like, not only which product wins a feature grid. If a regulator is driving this, start from the first row.
Why: ARCON is Mumbai-built with reporting shaped for RBI and SEBI CSCRF audits and support in the same time zone; CyberArk is the platform every regulator already recognises; Securden gives the same controls on an all-inclusive per-user number.
The trade-off: ARCON's platform breadth and CI/CD secrets are thinner than CyberArk's; CyberArk's licence and implementation are several times the cost. The regulator cares that privileged access is controlled and evidenced — not whose logo is on it.
Why: CyberArk Secrets Manager is the only purpose-built machine-identity platform here — pipelines, containers and application-to-application credentials brokered without a human. The full vaults store application credentials but are not CI/CD-native.
The trade-off: It is a second product with its own project and its own quote. Buying only the human vault and hoping it covers pipelines is how the machine half stays unsolved for two more years.
Why: BeyondTrust's per-managed-asset meter (about $157 per asset per year on the US GSA schedule) suits a small team over a large estate; Securden's per-user-only model suits the same shape from the other direction; ARCON quotes both dimensions in INR.
The trade-off: The two meters invert: per-asset is cheap for five admins over 500 servers and expensive for 200 admins over 50; per-user is the reverse. Model both on your real numbers before reading a quote.
Why: CyberArk Vendor PAM gives biometric-verified, VPN-less access priced per supplier; BeyondTrust Privileged Remote Access brokers and records the session for insiders and vendors alike.
The trade-off: Per-vendor pricing is cheap at ten suppliers and painful at two hundred; the brokered-session products price per user instead. Both beat issuing the supplier a VPN account nobody reviews.
Why: All three are PEDM: they take standing local administrator rights away and elevate named applications instead. BeyondTrust extends the same model to Unix and Linux servers.
The trade-off: None of these vaults anything. If the finding was about server, database or network credentials, PEDM does not answer it — that is the vault, and it is a separate purchase.
Why: Okta Privileged Access puts just-in-time server and cloud access under the identity, policy and lifecycle you already run; One Identity Cloud PAM Essentials is the vendor-neutral SaaS equivalent.
The trade-off: Okta's version assumes an Okta-centric estate and does not reach network devices, mainframes or the legacy long tail. If those matter, you are buying a classic vault regardless of who runs your SSO.
Why: Securden's all-inclusive per-user pricing and miniOrange's low INR entry point (workforce identity published from ₹180 per user per month, PAM quoted on top) are the two fastest routes to a working vault; Cloud PAM Essentials needs no appliance.
The trade-off: All three are flagged unverified above 1,000 privileged accounts — not ruled out, but ask for a reference at your size before signing a three-year term.
Why: One Identity pairs Safeguard with Identity Manager more tightly than anyone here; CyberArk and Okta each sell governance beside the vault on one platform.
The trade-off: One platform means one negotiation and one throat to choke — and one vendor's roadmap for two disciplines that are usually run by different teams on different timelines.
Every product here secures privilege. They differ in whose privilege — a person’s or a process’s — and in what you are billed for. Place each on both before comparing quotes.
Scope 1
The human vault
Credentials a named person checks out, brokered and recorded: domain admins, root, network gear, database owners, cloud consoles. The classic purchase, and what the regulators' language describes.
Scope 2
The machine vault
Secrets requested by applications, pipelines and containers — unattended, constantly, with no session to record. Purpose-built at CyberArk Secrets Manager; served but not CI/CD-native at the full vaults.
Scope 3
The endpoint (PEDM)
No vault: an agent removes standing local admin and elevates named applications. A separate audit finding, a separate budget, and frequently mistaken for the vault.
Scope 4
The access path
How administrators and suppliers reach production at all — brokered, recorded sessions instead of VPN and a jump box. Sold alongside the vault, sometimes instead of it.
The onboarding test
Ask these before the feature demo, in this order.
The India layer
ARCON is the India-built option — stated factually, including where it is weaker.
PAM scales by accounts onboarded, not licences bought. The bill follows the meter; the timeline follows how many owners you have to find.
Getting started is the constraint
Put this in your PoC
Vault the domain administrator account and have someone use it through the broker for a week. If they route around it, the product is wrong or the workflow is.
Coverage and ownership are the constraint
Put this in your PoC
Ask for a named reference at your size and industry, and ask them how long onboarding actually took versus the plan.
The machine half and the evidence are the constraint
Put this in your PoC
Count your non-human identities and your human ones. If the first number is larger and only the second is vaulted, you have found the next project.
CyberArk, BeyondTrust, ARCON, One Identity Safeguard and Okta document large estates; Securden, miniOrange, ARCON EPM, ARCON My Vault, Securden EPM and One Identity Cloud PAM Essentials are flagged unverified above 1,000 privileged accounts. Where a specific product strains for your estate: [TechBag to confirm].
The vault holds credentials, workflows, approvals and years of recordings. None of it moves. Switching is the original onboarding project run a second time, with the first platform still live.
Re-onboarding
Every account is discovered, owned, connected and tested again on the new platform. The plan that took two quarters takes two quarters.
The recordings
Session recordings live in the old platform's format and storage. Audit and legal retention decide how long you keep it running read-only after the switch.
Integrations and connectors
Ticketing approval flows, SIEM feeds, directory joins and custom connectors are per platform and rebuilt from scratch.
The overlap
Both vaults run until every account is migrated and rotated. Two PAM bills for two quarters is the honest cost of not leaving a gap in the control the regulator asked for.
Re-onboarding effort, recording retention and overlap cost for your estate: [TechBag to confirm] — TechBag scopes it from your account inventory and audit retention rules.
What you may already hold, the products priced on their own meters at three estate sizes in USD and INR, and what the licence line leaves out — which, for PAM, starts with the onboarding project.
Four places privileged control may already sit. Two are real; none is a vault for your infrastructure.
If what you own covers the accounts that actually worry your auditor, we say so. It costs us a sale and saves you one.
Reported and published meters (INR for scale), worked at three estate sizes. The meters are not comparable — per privileged user, per managed asset and per target system can differ by 5× on the same estate, so each line states its own unit. The India-built and mid-market options are priced explicitly, because no other comparison does.
The meters, side by side — why these numbers are not comparable
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
Discovery, finding an owner for every account, connectors, application testing and the rotation exceptions — measured in quarters at enterprise scale and the single largest hidden number in this category. Your figure: [TechBag to confirm].
Full recording is video-scale data with a retention policy attached. It is not in the licence, it grows with adoption, and the audit that asks for playback also asks how long you keep it. Size it before go-live.
The emergency path, tested; the application whose credential cannot rotate on a schedule; the legacy system that needs a bespoke connector. Every deployment has them, no licence includes them.
Documented behaviour and project outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in month nine.
Discovery finding thousands of accounts nobody will own
The scan succeeded and produced a list no team would claim. Onboarding stalls at the ownership conversation, not the technology — start it before the purchase order.
Break-glass procedures that were never tested
The vault, the directory or the network was down and nobody could reach the emergency credentials. Rehearse it quarterly; write down who holds what.
Session recording storage growing without a retention plan
Recording was switched on for everything; a year later storage was the largest line in the programme. Set retention by system class before go-live.
Agents that don't cover the one legacy system that mattered
The vault covered 95% of the estate and not the mainframe, the appliance or the industrial system the auditor asked about. Write the awkward list first, and test against it.
Buying PAM and never getting past the first fifty accounts
The domain admins went in and the project stopped. The remaining thousands are service accounts — which is the machine-identity problem wearing a different hat.
PEDM bought to answer a vault finding
Local admin rights were removed from laptops; the audit was about database and network credentials. Different product, different budget, same brochure vocabulary.
Rotation breaking the application nobody documented
A credential rotated on schedule and a batch job failed at 3am. Application-aware exceptions are a design decision, not a support ticket.
The pipelines never entering the vault
Human accounts are governed; CI/CD variables, container images and cloud workload identities are not. Non-human identities outnumber humans in most estates — and are usually outside the programme entirely.
Vendor-neutral. No gated content.