IdentityMesh Vault

Stop buying PAM as a second product.

Privileged checkout, rotation, and tamper-evident audit — built into the identity platform you already deploy for synchronization. No second vendor. No second agent. No second contract.

IM_VaultAuditEventsappend-only
  1. 0412Nominatedoperator7f3a…91c291c2…b04e
  2. 0413Approvedadmin91c2…b04eb04e…3d71
  3. 0414CheckedOutoperatorb04e…3d713d71…e8a9
  4. 0415Rotatedvault3d71…e8a9e8a9…5c10
  5. 0416CheckedInoperatore8a9…5c105c10…a27f
chain verified · 5 events · 0 gaps
  • 1product, not two
  • 0extra agents on your endpoints
  • $0add-on module fees
  • Daysto stand up, not months

The vault lives where the identities live.

CyberArk and Delinea sell a standalone vault that you then integrate with your identity stack. IdentityMesh Vault is the identity stack. It governs credentials for accounts already represented through IdentityMesh connectors, encrypts material through the existing ISecretStore, and decides who may request an account from the same mesh objects and group memberships the connectors already imported.

One deployment.One audit chain.One operations model.

How IdentityMesh Vault compares.

CriterionIdentityMesh VaultCyberArk PAMDelinea Secret Server
DeploymentModule of the identity platform you already runStandalone platform (Vault + CPM + PSM + PVWA)Standalone Secret Server, on-prem or Cloud
Time to stand upDaysMonths, with dedicated adminFaster than CyberArk, still a separate rollout
LicensingIncluded with IdentityMeshPer privileged account + per-module add-onsPer user, tiered; Cloud Platinum sold at premium
Typical cost / user / yearIncluded~$600–$1,400~$45–$110 Server; Cloud materially higher
RotationPer-target setters for AD (LDAPS), SQL logins, and Entra ID (Graph); owner-provided or blind nomination; per-policy schedule with failure backoffCPM plug-ins per platformDiscovery + remote password changers per platform
Secret storeExisting Azure Key Vault, DPAPI, or HashiCorp-backed ISecretStoreProprietary Vault applianceEncrypted DB with HSM options
AuditExtends the ER-005 append-only hash chainSession recording + SIEM exportEvent subscriptions + SIEM export
RolesExisting Viewer / Operator / Admin get scoped Vault permissionsMultiple product roles across modulesDistinct roles per Secret Server function

Competitor pricing reflects publicly published benchmarks. Contact us to model your specific quote.

Built for the buyer, not the box.

IT & identity

Cut PAM from a project to a checkbox.

Your CyberArk quote asks for a vault appliance, CPM, PSM, PVWA, and a dedicated admin. IdentityMesh Vault ships as a module of the sync engine you already own. Nominate an account, check it out, roll it back in — same UI, same roles, same install.

Migration

One .NET replacement covers sync and vaulting.

You already picked IdentityMesh to retire Microsoft Identity Manager. Adding CyberArk or Delinea on top puts you back into the two-product operations you were trying to escape. Vault lives in the same repos, ships in the same MSI, and audits into the same ER-005 hash chain.

Security & risk

Tamper-evident audit as a default, not an add-on.

Vault events extend the ER-005 append-only hash chain — its column order is frozen because reordering it would invalidate prior verification. One active checkout is enforced by policy and a filtered unique index. A missing source account locks the record instead of silently de-vaulting on transient import failure.

Seven decisions we didn't make lightly.

Reuse the shipped secret abstraction

Vault uses the existing ISecretStore — Azure Key Vault, DPAPI, or HashiCorp-backed depending on your deployment. No second KEK configuration system.

Rotate through a setter per target, or refuse

Rotation is delegated to the IVaultPasswordSetter registered for the connector type: Active Directory over LDAPS, a SQL login over its own connection, an Entra ID user over Graph. A connector type with no setter is refused at nomination rather than half-supported. The new password is written to the secret store under a pending reference before it touches the target, so a crash mid-rotation never loses a live credential.

OwnerProvidedBlindRotation

One active checkout per account

Policy and a filtered unique index enforce a single active session per account. Row-version concurrency and idempotent request identifiers protect against API races and client retries. A credential is revealed strictly once, through a one-time URL that is claimed before the secret is read.

Access by relationship, not by list

A Vault scope binds accounts to mesh groups. Who may request an account is derived from group membership the mesh already holds, imported from AD or built by Composer rules, instead of a hand-maintained safe. Accounts in no scope are restricted by default, and vault.admin does not bypass the rule on checkout.

Missing source locks — it does not delete

A missing source account blocks new checkouts and preserves its audit history. A transient import or replication failure cannot cause a vaulted account to silently disappear.

Existing audit semantics stay consistent

Vault seeds vault.audit.read for the existing Viewer role rather than adding a new Auditor role. Admin and Operator receive broader Vault permissions.

Audit joins the ER-005 hash chain

IM_VaultAuditEvents sits alongside IM_AdminAuditEvents and IM_ObjectAuditEvents in the append-only hash chain. Column order is frozen — reordering would invalidate verification of prior events.

What Vault does — and what it doesn't.

Marketing pages that claim everything are worth nothing. Here is the current scope, honestly.

In scope, shipping today

  • Privileged-account nomination, approval, checkout, and check-in, with a one-time credential reveal
  • Owner-provided or blind rotation for Active Directory, SQL logins, and Entra ID users
  • Rotation on check-in, on expiry, on demand, and on a per-policy schedule with failure backoff
  • Vault scopes that grant access by mesh group membership
  • Tamper-evident audit joined to the ER-005 hash chain
  • Scoped Viewer / Operator / Admin permissions, plus a vault-only User role

Refused rather than half-supported

  • Refused at nominationAccounts on connector types with no password setter, today Okta, Workday, and File, cannot be nominated. Marking an account fresh while its exposed password stays live would be worse than saying no.

Out of scope for v1

  • Privileged session recording (PSM equivalent)
  • Endpoint privilege management
  • Cloud infrastructure entitlements management

If session recording is a hard requirement, pair Vault with a session-recording tool of choice or stay with your current PAM for that workload. We would rather be clear than complete.

Compare your PAM renewal line by line.

Send us your CyberArk or Delinea quote. We'll map each line item to what's already included in IdentityMesh Vault — and be honest about what isn't.

Pricing benchmarks: Vendr and Vendor Benchmark 2026 (CyberArk, Delinea). Deployment complexity: Comparisec and StrongDM comparisons. Gartner Peer Insights review counts as of 2026.