Platform
Privileged Identity Management
Standing administrator access is one of the most common gaps in enterprise identity programs. Replace it with time-bound elevation, separation of duties, and automatic cleanup when the window closes.
The problem it solves
Standing admin roles create always-on privilege, weak ticket linkage, and cleanup projects that never finish.
Custodeum PIM replaces that with just-in-time elevation, SoD, ITSM evidence, and automatic revoke when the window closes.
- ·Always-on privileged roles
- ·Approvals outside the path
- ·Cleanup is a project
- ·Thin or missing ticket link
- ·Just-in-time elevation
- ·SoD and dual control
- ·Auto-revoke at window end
- ·ITSM create or attach
How elevation works
Users select role, duration, and justification. Approvers act from email, User Portal, or Teams.
Custodeum grants the entitlement, holds the active window, supports extensions, and revokes at end time with every step logged.
Every step logs the actor, approver, ticket, and entitlement across Okta, Entra, AD, and Google Workspace.
| Standing admin | Custodeum PIM |
|---|---|
| Always-on privileged roles | Just-in-time elevation |
| Approvals outside the path | SoD and dual control in-flow |
| Cleanup is a project | Auto-revoke at window end |
| Thin or missing ticket link | ITSM create or attach |
The same employee may hold privileged accounts across Okta, Entra, and Active Directory. Custodeum binds them to a single login with eligibility and approvers configured per system.
- Okta admin roles and privileged groups
- Entra directory roles
- AD privileged groups via agent
- Google Workspace where enabled
Approvers act without admin console access from the User Portal, Microsoft Teams adaptive cards, or the full operator view.
- User Portal PIM Approvals
- Teams Self-Service Request Hub
- Separation of duties enforced
- Requesters cannot approve own requests
Attach existing ServiceNow or Jira tickets or create them automatically on request, grant, and revoke.
- Catalog variable mapping
- Extension requests reuse original ticket
- ITSM stays system of record
Global settings, per-system eligibility rules, privileged account inventory, and filterable audit log with approver identity on every decision.
- Emergency break-glass paths
- Vault integration for checkout
- Scheduled and extension requests
- Exportable CSV audit log
Why PIM belongs in your identity operations platform
Point solutions for privileged access often sit outside governance and support. Custodeum PIM shares the same identity model, Teams fabric, ticketing, and audit store as campaigns and delegated support.
One identity model, one audit store, not another privileged-access silo
Who it is for
| Audience | Outcome |
|---|---|
| Security and IAM | Eliminate standing privilege with evidence |
| Approvers | Act in portal or Teams without admin console |
| Service desk | Tickets stay the system of record |
| Auditors | Approver identity on every elevation |
Where it fits in Custodeum
PIM is time-bound elevation for people; Agent Gateway covers machine-initiated identity actions.
Self-service request and approve.
Learn moreAdaptive card approvals.
Learn moreBrokered actions for agents.
Learn moreRBAC for who may manage PIM.
Learn moreElevation evidence for reviews.
Learn moreRecertify what still stands.
Learn moreReplace standing admin with governed elevation
Walk through request, approve, grant, extend, and revoke across Okta, Entra, and AD.