# Privileged access without a single password to share.

> Just-in-Time privileged sessions with verified identity, device, and location, approval on connection, and full recording.

URL: https://www.ironchip.com/en/privileged-access

Product · Privileged access (PAM)


Your administrators and vendors access servers, databases, and Kubernetes when needed, with their identity, from their device, and from an authorized location. No VPN, no shared accounts, and every session recorded. Included in Ironchip Premium.

[Request a pilot](https://www.ironchip.com/en/talk-sales) See how it works

_Example of a privileged access request pending approval._

## What changes for your team from day one.

### Audits with evidence

Each session is recorded with who requested it, who approved it, where it was accessed from, and what was executed. What ENS, NIS2, or DORA require, without screenshots.

### Vendors without shared accounts

The external technician accesses with their identity, on their device, and in their time window. When done, access disappears automatically.

### No VPN or open ports

Ironchip Connect exits from your network toward Ironchip. Your servers are not published to the internet, not even to us.

### A stolen credential opens nothing

Without the registered device, without the authorized location, and without approval, an intercepted username and password are useless.

### Passwords no one knows

They are set on login and changed on logout. No one types them, no one copies them, and no one takes them when changing companies.

### On top of what you already have

The same directory, the same console, and the same factors that Ironchip already uses to protect your applications.

## The vault protects the secret. We keep it out of the way.

No one types or sees a privileged credential. Access is decided at the moment, with context, and what the system needs to connect is stored encrypted and rotated beyond reach.

| | Traditional PAM | Ironchip PAM |
|---|---|---|
| Privileged credentials | Stored in vault, shared by checkout | No one sees them: the broker supplies them at connection time and can rotate them after each session |
| Privileges | Permanent or by checkout | Just-in-Time: an approved window that closes on its own |
| Remote access | VPN + jump server | Browser or your own client (ssh, psql, kubectl) with a single-use ticket |
| If the login is stolen | Access to the vault and everything it contains | Without the device, safe zone, and access factors, it does not open |
| Network | Published inbound ports or VPN | Outbound only: Ironchip Connect opens the tunnel from inside |
| Deployment | Multi-month project | On top of the IdP, directory, and console you already have |

## A single path to each machine, and Ironchip decides at each step.

The person requests access in the console and connects with a single-use ticket. The broker holds the connection while Ironchip checks device, location, risk, and approval; only then does it set the credential and start recording.

**Person**: Browser, or their own client: ssh, psql, mysql, RDP, VNC, kubectl. Your network

**Ironchip console**: Access, factors, approvals, location, risk, and recordings. The same platform console. Ironchip

**Ironchip PAM broker**: The only entry point: holds each connection, supplies the credential, and records the session. Ironchip

**Secrets store**: Credentials and secrets encrypted, each company in its own space. The broker reads and keeps no copy. Ironchip

**Your machines**: Servers, desktops, databases, and Kubernetes. With Ironchip's agent, optional, which only opens outbound connections. Your network

1. The person requests access in the console, in My access, with a reason if the policy requires it.
2. Connects with a single-use ticket, from the browser or with their own client.
3. The broker holds the connection and asks Ironchip: access, factors, risk, and approval.
4. If approved, the broker reads the credential from the store. The person never sees it.
5. Opens the session and records it from start to finish.
6. The agent reports and receives rules over HTTPS. With Ironchip Connect, your network opens no inbound port.

SSH RDP VNC PostgreSQL MySQL Kubernetes From the browser or with your usual client

## Just-in-time approval, at the moment you choose.

No one approves their own request or the same one twice, and the window closes automatically. The approval also counts as a factor for your SSO applications.

On request: approved once

### One approval opens a window.

- requests
- approve
- window open
- connects
- connects
- connects
- closes by itself

Within the window the person enters as many times as they want. Each connection still goes through the broker and through factor and risk checking.

On connect: each connection asks

### Each connection is held until they decide.

- requests
- connects: held
- approve this connection
- enters
- another connection: waits

The approver sees this person, from this address, right now. It's the mode for machines where each entry counts.

## Each session, with its full history.

Screen, commands, and decisions on a single timeline. You can watch it live, stop it instantly, and save it as evidence.

Live **prod-db-01** PostgreSQL · external technician · 00:42:18 End session


```
$ psql -h prod-db-01 billing
billing=# REINDEX TABLE invoices;
REINDEX
billing=# \q
$ sudo systemctl restart billing-api
⏸ Held by Ironchip: requires approval
✓ Approved by the systems administrator
```


- 10:02 **Connection allowed** Device, safe zone, and risk correct · approved by the systems administrator
- 10:05 **Process started** psql, detected by the device agent
- 10:31 **sudo held** systemctl restart billing-api, awaiting approval
- 10:33 **sudo approved** Logged who authorized it and which rule applied
- 10:44 **Session closed** Recording saved · password changed

**Linux and macOS: each sudo asks**: It is allowed, denied with a reason, or held until someone approves it.

**Windows: permitted programs only**: Rules by program applied with AppLocker during the session, even if renamed.

**Live monitoring**: Who is in, which machine, and from where, with the option to terminate the session instantly.

## Ironchip Connect: we reach your machines without opening a single door.

A lightweight connector inside each site opens an encrypted outbound tunnel toward Ironchip. Through it, and only through it, arrives the broker.

**Your site · Madrid**

- server 10.0.0.5
- database 10.0.0.8 Ironchip Connect

Outbound only encrypted WireGuard tunnel

**Ironchip**: Ironchip PAM broker. Authorizes the networks of each site.

Outbound only its own tunnel, no IP conflicts

**Another company**

- server 10.0.0.5
- desktop 10.0.0.9 Ironchip Connect

**No inbound**: Your network publishes no ports. The connector only opens outbound connections.

**Your ranges, no conflicts**: Even if another company uses the same private addresses, each site follows its own path.

**Direct when possible**: If the network allows it, the tunnel goes direct; if not, it passes through a relay without losing encryption.

## The same vault, also for applications and clouds.

### Applications and pipelines

Compatible with the Vault API: your code and CI read its secrets from Ironchip without changing a line, with database credentials that expire automatically.

### Passwords for people

A manager for what must be known, like the router at a head office. It's shared by groups and every time someone reveals it, it's recorded.

### AWS, Google Cloud, and Azure consoles

Protected with Ironchip's SSO and on-demand temporary credentials, instead of eternal keys distributed across laptops.

## Frequently asked questions about privileged access

### What does a PAM without shared passwords mean?

That people enter servers, databases and Kubernetes without knowing or typing the credential. Ironchip supplies it at connect time, can change it when the session ends, and no one takes it when they change companies.

### How do I give access to an external vendor without a VPN?

The vendor requests access to a specific machine, an approver approves it, and they enter via the browser or their own client during a time window. The session is recorded and access closes when the window ends.

### Do I need to open firewall ports?

No. Ironchip Connect is installed within each site and opens an encrypted outbound tunnel to Ironchip. Servers are not published on the internet.

### Can a session be monitored or terminated in real time?

Yes. Terminal and desktop sessions are fully recorded, can be viewed as they happen, and terminated instantly. Each sudo or program executed is on the same timeline.

### What systems does it cover?

SSH, RDP, VNC, PostgreSQL, MySQL and Kubernetes, from the browser or with standard clients. The Ironchip agent also controls which commands and programs are executed on Linux, macOS and Windows.

## Start with your 20 most critical accounts.

A pilot on the servers and accounts that concern you most, with your existing IdP and directory.

[Request a pilot](https://www.ironchip.com/en/talk-sales) [Technical documentation](https://docs.ironchip.com)
