TL;DR: Traditional PAM was built for static administrator credentials, but modern cloud infrastructure now relies on short-lived workloads, service accounts, APIs and automation, according to P0 Security. The architectural shift is toward identity-native authorization and runtime policy enforcement, which makes standing privilege and vault-centric control models increasingly inadequate.
NHIMG editorial: based on content published by P0 Security: The evolution of Privileged Access Management
Questions worth separating out
Q: What breaks when privileged access is controlled only by a vault?
A: A vault controls where the credential sits, but not what happens after the credential is released.
Q: Why does standing privilege increase risk in distributed cloud and contractor-heavy environments?
A: Standing privilege increases risk because access persists after the original need has passed, especially when people move teams, contractors change roles, or credentials are reused.
Q: How do teams know whether privileged access is actually being enforced at runtime?
A: Teams should look for evidence that elevated access is issued only for a defined task, context, or session and that persistent elevation has been removed from routine workflows.
Practitioner guidance
- Map privileged workflows that still depend on vault retrieval Identify where elevated access is still mediated through stored secrets, proxy approvals, or long-lived credentials rather than runtime policy.
- Replace standing privilege with task-scoped access windows Define which privileged operations can be issued only for a specific job, session, or deployment step, then remove default elevation from the underlying identity.
- Audit service accounts and automation for permanent elevation Review non-human identities for access that persists across environments or remains active after the operational need has ended.
What's in the full article
P0 Security's full whitepaper covers the operational detail this post intentionally leaves for the source:
- Architectural examples of how runtime access enforcement replaces vault-mediated approval flows
- Practical discussion of how cloud-native privilege models differ across workloads, APIs, and service accounts
- The paper's own framing of how organisations can modernise without disrupting existing operations
- Additional detail on the next-generation PAM architecture and how the vendor positions it
👉 Read P0 Security's whitepaper on the evolution of privileged access management →
Privileged access in the cloud era: what is changing for teams?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Vault-centric PAM is no longer the right abstraction for cloud privilege. The whitepaper describes a world where privileged actions are executed by software, not just administrators, so the old vault-first model becomes too slow and too coarse. That does not just create implementation drag. It changes the control plane from credential custody to runtime authorisation, which is where modern privileged access decisions now belong. Practitioners should treat vaults as one component, not the governance model itself.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- 73% of vaults are misconfigured, leading to unauthorised access and exposure of sensitive data, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations treat PAM as a vault problem or an identity governance problem?
A: Organisations should treat PAM as an identity governance problem first, because the key issue is who or what can act, under what conditions, and for how long. Vaults still matter, but they are not sufficient when privileged actions happen through software identities, APIs, and ephemeral access paths.
👉 Read our full editorial: Runtime privileged access is replacing vault-centric PAM in cloud environments