Privileged credentials, controlled and accountable
Syteca Privileged Access Management is a unified vault, access broker, and session recorder for the shared admin accounts your team relies on — domain administrators, root accounts, database superusers, service accounts. It eliminates the practice of passing privileged passwords around in spreadsheets, Slack messages, or sticky notes, and replaces it with a controlled flow: credentials are stored encrypted, access is granted by role and approval, sessions are brokered without ever revealing the password, and every action is auditable. PAM matters most for the accounts that, if compromised, would let an attacker (or a careless insider) move freely across your environment. Auditors ask about how they’re managed. Insurers ask. Regulators ask. Syteca PAM is the answer.Use Syteca PAM if you need to:
- Stop sharing privileged passwords in chat, email, or spreadsheets.
- Onboard and offboard contractor / third-party access in minutes, not days.
- Rotate privileged passwords automatically on a schedule — or after every use.
- Record what privileged users actually do during a session, for audit and incident response.
- Meet compliance requirements (PCI DSS, HIPAA, SOC 2, ISO 27001) that mandate privileged access controls.
PAM is available only with an activated license serial key that includes the Password Management application and PAM seat licenses. Seat licenses must be assigned to users before they can use any PAM functionality.
How it works

The Password Management page — secrets organized in folders, with the Launch button surfacing per-secret to connect via the configured Connection Manager.
1
Store credentials in secrets
Privileged account credentials are stored encrypted in secrets, organized into folders with role-based permissions.
2
Control who can use them
Permissions (Owner, Editor, PAM User) plus advanced permissions decide who can view, edit, and use each secret.
3
4
Rotate, check out, and audit
Rotate passwords automatically, restrict a secret to one user at a time, and audit every brokered session.
What you can do
1
Store secrets in a hardened vault
Workforce Password Management (WPM) stores credentials in an encrypted vault scoped by user, role, and project. Permissions on a secret are independent of permissions on the system it unlocks.
2
Broker access without exposing the password
A user can connect to a target system through the Desktop or Web Connection Manager. The credential is injected by Syteca; the user never sees it.
3
Rotate credentials on a schedule or on demand
Remote Password Rotation updates the target system and the vault in one transaction, with verification and rollback.
4
Audit every session
Every connection brokered through Syteca is recorded with the same fidelity as a User Activity Monitoring session. The Session Player and search work identically.
5
This is a new step which will be removed
This is a new step which will be removed.
Set up Password Management
Licensing, LDAP, seat licenses, and the configuration order to get started.
Add a secret
Create and configure a secret for any account type.
Connect using a secret
Use a secret to connect to a privileged account.
Discover accounts
Scan the network and onboard accounts into secrets automatically.
System notes
- The Desktop Connection Manager requires .NET Framework 4.8 on the Client computer.
- A jump server computer is only needed if two or more concurrent sessions are required on the Client computer running the Desktop Connection Manager; a Windows Server operating system is recommended for it.
Related
Permissions for secrets
Owner, Editor, and PAM User roles explained.
Application Credentials Broker
Retrieve secrets from applications via REST API.