Platform

Privileged Identity Management

Standing administrator access is one of the most common gaps in enterprise identity programs. Replace it with time-bound elevation, separation of duties, and automatic cleanup when the window closes.

The problem it solves

Standing admin roles create always-on privilege, weak ticket linkage, and cleanup projects that never finish.

Custodeum PIM replaces that with just-in-time elevation, SoD, ITSM evidence, and automatic revoke when the window closes.

Standing admin
  • ·Always-on privileged roles
  • ·Approvals outside the path
  • ·Cleanup is a project
  • ·Thin or missing ticket link
Custodeum PIM
  • ·Just-in-time elevation
  • ·SoD and dual control
  • ·Auto-revoke at window end
  • ·ITSM create or attach

How elevation works

Users select role, duration, and justification. Approvers act from email, User Portal, or Teams.

Custodeum grants the entitlement, holds the active window, supports extensions, and revokes at end time with every step logged.

1
Request
Role & duration
2
Approve
Portal or Teams
3
Grant
Auto-assigned
4
Active
Time-bound
5
Extend
Optional renew
6
Revoke
Auto at expiry

Every step logs the actor, approver, ticket, and entitlement across Okta, Entra, AD, and Google Workspace.

Standing adminCustodeum PIM
Always-on privileged rolesJust-in-time elevation
Approvals outside the pathSoD and dual control in-flow
Cleanup is a projectAuto-revoke at window end
Thin or missing ticket linkITSM create or attach
Multi-System, One Person

The same employee may hold privileged accounts across Okta, Entra, and Active Directory. Custodeum binds them to a single login with eligibility and approvers configured per system.

  • Okta admin roles and privileged groups
  • Entra directory roles
  • AD privileged groups via agent
  • Google Workspace where enabled
Approval Everywhere

Approvers act without admin console access from the User Portal, Microsoft Teams adaptive cards, or the full operator view.

  • User Portal PIM Approvals
  • Teams Self-Service Request Hub
  • Separation of duties enforced
  • Requesters cannot approve own requests
Ticketing as Evidence

Attach existing ServiceNow or Jira tickets or create them automatically on request, grant, and revoke.

  • Catalog variable mapping
  • Extension requests reuse original ticket
  • ITSM stays system of record
Administration & Audit

Global settings, per-system eligibility rules, privileged account inventory, and filterable audit log with approver identity on every decision.

  • Emergency break-glass paths
  • Vault integration for checkout
  • Scheduled and extension requests
  • Exportable CSV audit log

Why PIM belongs in your identity operations platform

Point solutions for privileged access often sit outside governance and support. Custodeum PIM shares the same identity model, Teams fabric, ticketing, and audit store as campaigns and delegated support.

Governance
Automation
Support
Teams
PIM
Audit

One identity model, one audit store, not another privileged-access silo

Who it is for

AudienceOutcome
Security and IAMEliminate standing privilege with evidence
ApproversAct in portal or Teams without admin console
Service deskTickets stay the system of record
AuditorsApprover identity on every elevation

Where it fits in Custodeum

PIM is time-bound elevation for people; Agent Gateway covers machine-initiated identity actions.

Replace standing admin with governed elevation

Walk through request, approve, grant, extend, and revoke across Okta, Entra, and AD.