Buying, Building and Using What You Have
The platform capabilities you already own cover more than expected. What a product genuinely adds, and when building is defensible.
Analysis
PAM products are expensive and cover real ground. A significant part of what they do is available in platforms most organisations already run.
What you probably already have
Directory-based just-in-time group membership, available natively in modern directory and cloud identity platforms.
Cloud privileged identity management, included in several enterprise identity licences and frequently unused.
Managed service accounts with automatic password management.
Sudo policy management through configuration management.
SSH certificate authorities, which are a configuration exercise rather than a purchase.
Platform audit logging, everywhere, usually under-collected.
Local administrator password management, available natively on major platforms.
Deploying what you already own is the cheapest first move and it is routinely skipped in favour of a procurement.
What a product adds
Session brokering with credential injection, across many protocols, which is genuinely hard to build.
Session recording at scale with search and retention management.
A workflow layer: requests, approvals, expiry, review campaigns.
Broad connector coverage for systems you would otherwise handle individually.
Rotation across heterogeneous targets.
Reporting and audit evidence in a form auditors recognise.
The workflow and the connectors are the real purchase. The cryptography is not the hard part.
When building is defensible
A small estate where a handful of scripts and platform features suffice.
An unusual requirement no product meets.
Data that cannot leave your environment, which is a genuine constraint in some sectors.
Existing platform engineering capacity with a named owner for the next several years.
A cloud-only estate, where native tooling covers most of the ground and a traditional product fits badly.
When it is not
When nobody will own it. An unmaintained broker is worse than none, because people rely on it.
When the workflow is the requirement. Requests, approvals, expiry and review campaigns are most of a product and are tedious to build.
When breadth is the requirement, because connector coverage is where the vendor's years of work sit.
When the driver is avoiding a licence cost smaller than the engineering time.
The middle path
Use native platform capabilities for everything they cover.
Buy for session brokering, recording and the workflow layer.
Build the integration glue, which nobody sells and which determines whether the whole thing fits your processes.
This is the arrangement most organisations should aim at, and it requires deciding what you already own before going to market.
Before procuring
Complete the inventory, so the scope is real.
Deploy the native capabilities and see what remains.
Write the requirement from what remains, which is usually narrower and cheaper than the initial assumption.
Trial on your actual estate, particularly on the awkward systems rather than the easy ones, because the awkward ones determine whether coverage claims hold.
What to deploy before going to market
Native capabilities cover more than expected and cost nothing extra.
Local administrator password management, available on major platforms.
Cloud privileged identity management, included in several enterprise identity licences.
Managed service accounts with automatic password handling.
Directory-based time-bound group membership.
Sudo policy through configuration management.
SSH certificate authority, which is configuration rather than purchase.
Platform audit logging, collected and shipped.
Deploy these, then write the requirement from what remains. It is usually narrower and cheaper than the initial assumption.
The three-year question
Asked before building anything, and it decides the answer.
Who maintains this when the author leaves? A named role with allocated time.
What happens when a platform API changes? Which it will.
Who notices when it silently stops working? This is the failure that produces a control everyone believes is in place.
What is the documented handover?
If any of these has no answer, buy, because a decayed internal broker is worse than none โ people rely on it.