TL;DR: Annual recurring revenue has surpassed $400 million, with SaaS now representing the majority of its ARR, while it expands AI-focused identity features such as shadow AI discovery, entitlement management, and real-time authorization across hybrid environments, according to Delinea. The deeper story is that PAM and identity security are moving toward broader governance of human, machine, and AI access, not just privileged session control.
Editorial analysis by NHI Mgmt Group, based on content published by Delinea: “Delinea Surpasses $400M in ARR and Expands Global Momentum with Strong First-Half 2025 Performance”.
By the numbers:
- Delinea says annual recurring revenue has surpassed $400 million.
- Delinea says its platform is the only identity security provider to commit to 99.995% uptime.
Key questions
Q: How should security teams govern AI access inside PAM programmes?
A: Security teams should treat AI access as part of the identity control plane, not a separate innovation stream.
Q: What breaks when shadow AI is not discovered early?
A: Teams lose sight of which agents exist, what they can reach, and which credentials they use.
Q: How do real-time authorization and traditional PAM differ?
A: Traditional PAM often governs access at the point of elevation or session start, while real-time authorization evaluates the current context each time access is used.
Practitioner guidance
- Map AI access paths into identity inventory Add shadow AI, AI service identities, and delegated entitlements to the same inventory process used for human and machine accounts so governance does not stop at known administrators.
- Split session control from lifecycle control Use separate governance rules for elevation, entitlement ownership, and access review so temporary privileged sessions do not mask persistent identity sprawl.
- Establish real-time authorization checkpoints Evaluate access decisions at use time across SaaS, cloud, and traditional infrastructure when the same identity can move between contexts quickly.
Bottom line: The article signals a category expansion, with PAM now being described as a broader identity governance layer for humans, machines, and AI access.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
PAM is becoming an identity governance layer, not a session-control layer: Delinea’s update reflects a category shift that many teams are already experiencing. Privileged access is no longer limited to interactive administrator sessions, because modern enterprises now need to govern machine identities, SaaS privileges, and AI-driven access paths as part of the same control model. The practitioner takeaway is that PAM programmes now compete or coexist with broader identity governance expectations.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations re-evaluate IAM and PAM for agentic AI deployments?
A: Yes, because agentic systems can inherit credentials and exercise privileged tools in ways that traditional IAM and PAM reviews do not fully capture. Organisations should reassess whether their current models account for ephemeral tasks, delegated authority, and machine-speed execution. The key test is whether access can be constrained to the exact task and revoked immediately afterward.
👉 Read our full editorial: Delinea's AI identity expansion signals a broader PAM shift