In traditional PAM workflows, permissions are often granted globally
to individuals based upon job role, and do not take into account
real-time risk factors, such as location, day or time. Password Safe
enables the dynamic assignment of just-in-time privileges via the
Advanced Workflow Control engine. Automatically evaluate the day, date,
time, location, and other contextual data when a user attempts to access
resources to make intelligent access decisions.
Policies can be extended to block password access to some managed
resources unless the request originated from the corporate network,
another approved source or only allow access to certain vendor accounts
if they originate from the vendor network.
These capabilities minimize standing privileges,
thereby minimizing opportunities for exploiting privileged credentials,
while ensuring that users have the right access according to the
context of their request.