TL;DR: Continuous machine and AI-driven access is pushing security away from vault-and-session privilege models toward per-request authorization, according to Pomerium’s analysis. That shift matters because static PAM assumptions break when software acts continuously and identity decisions must happen at the moment of action.
Editorial analysis by NHI Mgmt Group, based on content published by Pomerium: “Privilege Access Is the Past. Per Request Authorization Is the Future.”.
Key questions
Q: What breaks when privilege management is used for continuous machine access?
A: Privilege management breaks when the access pattern is continuous, because vaulting and session brokering assume a bounded human workflow.
Q: Why does per-request authorization reduce risk for workloads and agents?
A: Per-request authorization reduces risk because it limits each action to the exact context in which it is requested.
Q: How should security teams reduce standing privilege for non-human identities?
A: Security teams should replace persistent access with time-bound, task-scoped entitlements, then automate revocation when the task ends.
Practitioner guidance
- Map privileged workflows to request-level policy decisions Identify where workloads, APIs, and agents currently rely on standing privilege or brokered sessions, then move those paths toward per-request authorization at the resource boundary.
- Keep PAM for legacy and administrative access Preserve vaulting, approval workflows, and session brokering where human administration or regulated legacy systems still need them, but do not treat those controls as the primary layer for machine-operated systems.
- Separate human admin access from software access Assign different control patterns to people, service accounts, workloads, and AI agents so that machine activity is governed by runtime policy rather than human-style elevation assumptions.
Bottom line: Continuous machine activity exposes a mismatch between old privilege controls and how software now operates.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Per-request authorization is the structural answer to machine-speed identity behaviour. The article is correct that the old privilege model assumes access is episodic, reviewed, and returned. When workloads and agents act continuously, that assumption stops matching operational reality, so the security control has to move to the moment of action. Practitioners should recognise this as an access-model shift, not just a product category change.
A question worth separating out:
Q: Should organisations still use PAM for machine access?
A: Yes, but selectively. PAM still matters for legacy systems, administrative access, and regulated environments, yet it should not be the primary access layer for continuously operating software. For machines, the stronger model is continuous authorization tied to the specific request and its context.
👉 Read our full editorial: Request-based authorization is displacing privilege management