Skip to main content

Privileged credentials, controlled and accountable

Syteca Privileged Access Management is a unified vault, access broker, and session recorder for the shared admin accounts your team relies on — domain administrators, root accounts, database superusers, service accounts. It eliminates the practice of passing privileged passwords around in spreadsheets, Slack messages, or sticky notes, and replaces it with a controlled flow: credentials are stored encrypted, access is granted by role and approval, sessions are brokered without ever revealing the password, and every action is auditable. PAM matters most for the accounts that, if compromised, would let an attacker (or a careless insider) move freely across your environment. Auditors ask about how they’re managed. Insurers ask. Regulators ask. Syteca PAM is the answer.
Use Syteca PAM if you need to:
  • Stop sharing privileged passwords in chat, email, or spreadsheets.
  • Onboard and offboard contractor / third-party access in minutes, not days.
  • Rotate privileged passwords automatically on a schedule — or after every use.
  • Record what privileged users actually do during a session, for audit and incident response.
  • Meet compliance requirements (PCI DSS, HIPAA, SOC 2, ISO 27001) that mandate privileged access controls.
PAM in Syteca is built from two features that work together: Password Management (storing and using secrets) and Account Discovery (finding and onboarding accounts automatically). A separate REST API tool, the Application Credentials Broker (ACB), lets applications retrieve secret data securely without logging in to the Management Tool.
PAM is available only with an activated license serial key that includes the Password Management application and PAM seat licenses. Seat licenses must be assigned to users before they can use any PAM functionality.

How it works

Password Management page Secrets tab showing folder tree on the left and secrets grid with multiple secret types and per-row Launch buttons

The Password Management page — secrets organized in folders, with the Launch button surfacing per-secret to connect via the configured Connection Manager.

1

Store credentials in secrets

Privileged account credentials are stored encrypted in secrets, organized into folders with role-based permissions.
2

Control who can use them

Permissions (Owner, Editor, PAM User) plus advanced permissions decide who can view, edit, and use each secret.
3

Connect through a Connection Manager

Users reach the account through the Web or Desktop Connection Manager — the credential is injected, never shown.
4

Rotate, check out, and audit

Rotate passwords automatically, restrict a secret to one user at a time, and audit every brokered session.

What you can do

1

Store secrets in a hardened vault

Workforce Password Management (WPM) stores credentials in an encrypted vault scoped by user, role, and project. Permissions on a secret are independent of permissions on the system it unlocks.
2

Broker access without exposing the password

A user can connect to a target system through the Desktop or Web Connection Manager. The credential is injected by Syteca; the user never sees it.
3

Rotate credentials on a schedule or on demand

Remote Password Rotation updates the target system and the vault in one transaction, with verification and rollback.
4

Audit every session

Every connection brokered through Syteca is recorded with the same fidelity as a User Activity Monitoring session. The Session Player and search work identically.
5

This is a new step which will be removed

This is a new step which will be removed.

Set up Password Management

Licensing, LDAP, seat licenses, and the configuration order to get started.

Add a secret

Create and configure a secret for any account type.

Connect using a secret

Use a secret to connect to a privileged account.

Discover accounts

Scan the network and onboard accounts into secrets automatically.

System notes

  • The Desktop Connection Manager requires .NET Framework 4.8 on the Client computer.
  • A jump server computer is only needed if two or more concurrent sessions are required on the Client computer running the Desktop Connection Manager; a Windows Server operating system is recommended for it.

Permissions for secrets

Owner, Editor, and PAM User roles explained.

Application Credentials Broker

Retrieve secrets from applications via REST API.