Privileged access requirements checklist: every RFP category, row by row
Regulated buyers evaluate privileged access products with a long Request for Proposal (RFP) checklist. The checklist below follows the eleven categories those buyers use: auditing and reporting, deployment and support, discovery, disaster recovery and high availability, integrations, password management, secret workflow, security and compliance, session launching and monitoring, the Web API and scripting, and ease of use. Each row states how Analog Informatics Corporation (AIC) meets the requirement and whether it is available now.
AIC is one product. Privileged Identity Management (PIM) - vaulting, rotating, and propagating credentials - Privileged Access Management (PAM) - brokered and recorded sessions - and Privileged User Management (PUM) - endpoint privilege elevation and delegation - share one roster, one policy engine, and one audit trail. The rows below are not stitched together from separate products.
Auditing and reporting
| Requirement | How AIC meets it |
|---|---|
| Account permission reports | Report who can see, check out, or use each vaulted account, and through which role or set. |
| Trace every administrator and user action to a person and a time | Every action is recorded with the named person, the target, the outcome, and the server time. Windows Event Log and syslog carry the same record. |
| Out-of-the-box and on-demand reports for owners | Built-in reports for accounts, rotation, sessions, access, and audit events, run on demand. |
| Automated report queries | Saved report queries run on a schedule and deliver results. |
| Log creation, storage, analytics, and alerting | Audit log with search and filters, retention and archive, and alert rules. Forward to any Security Information and Event Management (SIEM) collector. |
| Email notifications | Email through the organization's mail server, including Microsoft 365 and Outlook, with message templates. |
| Event subscriptions and alerts | Subscribe people and groups to events and reports. |
| Inactive-account reporting | Report accounts with no recent logon, on demand or on a schedule. |
| Password history | Every prior password value is kept, encrypted, with who changed it and when. |
| Scheduled reports | Reports run on a schedule and are emailed or saved. |
| Security assessment reporting | Current State Compliance - the admin ledger of control-oriented findings with rescan - and the Assessment Binder export. |
| Self-monitoring, health check, and repair | The server checks its own services, storage, and connections, reports health, and repairs shipped reference data that is missing after an upgrade. |
| User audit report | All actions for one person over a date range. |
| Agentless auditor tools | Read-only auditor role in the console and the Assessment Binder. No software installed for the auditor. |
| Custom reports | Build reports from fields, filters, and grouping, and save them. |
| External auditing tool integration | Syslog (RFC 5424), Windows Event Log, and the REST API feed outside audit tools. |
| Ad-hoc user reports | Filter any report by person, system, or time and export it. |
| Dual control (four eyes) | A second person must approve before a credential is released. |
Deployment and support
| Requirement | How AIC meets it |
|---|---|
| Data segregation between customers | Each customer runs in its own instance or enclave with its own database and keys. |
| Same features in the cloud and on premises | One server build runs in the cloud, on premises, and air-gapped. |
| Network zone segmentation | Engines and agents run inside each zone and connect out to the server. |
| Centralized administration | One web console for every module. |
| On-premises deployment | Windows and Linux server installers. |
| On-site engines to reach untrusted networks | Agents, discovery engines, and session gateways run in the remote network or demilitarized zone (DMZ). |
| Password masking at logon | Passwords are injected into sessions and never shown unless a person with permission reveals them. |
| Cloud (SaaS) deployment | Hosted on Microsoft Azure. Other clouds are listed on the deployment page. |
| Selective, targeted discovery refresh | Re-run discovery for one system, one set, or one account type. |
| Support for current Payment Card Industry (PCI) controls | Rotation, access review, session recording, and audit reports that PCI Data Security Standard audits ask for. |
| IP address restrictions | Limit console and API access to listed networks. |
| Notice before a hosted upgrade | Release notes and notice before hosted upgrades. |
| Pre-upgrade testing site | A staging site to test an upgrade before production. |
| Optional agent | Agentless management over WinRM and SSH, or the Agent where an agent is preferred. |
| 24/7 support with a service level agreement | Partner and customer support with escalation to engineering. A 24/7 service level agreement is planned. |
Discovery
| Requirement | How AIC meets it |
|---|---|
| Active Directory synchronization | Read users, groups, and computers from Active Directory over verified LDAPS. |
| Automatic discovery of privileged accounts | Scan systems for local and domain accounts and privileged group membership. |
| Windows, Unix and Linux, LDAP, and Active Directory accounts | Discovered and managed. |
| Database accounts | Discovered and managed on the common database platforms. |
| Network device and appliance accounts | Discovered and managed over SSH, Telnet scripts, and browser automation. |
| Discovery rules that auto-manage credentials | Rules bring matching accounts under management automatically. |
| Service accounts | Find every service, scheduled task, application pool, COM+ application, and configuration file that uses an account, and update each one when the password changes. |
| Pruning obsolete accounts | Remove accounts that no longer exist on the target. |
| Decommission devices based on Active Directory status | Retire systems that are disabled or removed in Active Directory. |
| Discover SSH certificates on targets | Find SSH certificates on managed systems. |
| Custom account types | Define custom platforms with scripts, browser automation, or the API, managed or manual. |
Disaster recovery and high availability
| Requirement | How AIC meets it |
|---|---|
| Automatic backups | Scheduled, encrypted database and configuration backups. |
| Cloud architecture | Runs as a hosted service on Microsoft Azure. |
| On-premises recovery copy of the cloud service | Export an encrypted backup to the organization's own storage. |
| Break-glass emergency access | Sealed emergency accounts with recorded use and forced rotation afterward. |
| Load balancing | Spread console and API load across several servers. |
| High availability and clustering | Run several servers so service continues if one fails. |
| Geo-replication for recovery | Keep a live copy in a second region. |
Integrations
| Requirement | How AIC meets it |
|---|---|
| Active Directory, Microsoft Entra ID, and LDAP | Directory sign-in, discovery, and group sync. |
| Amazon Web Services (AWS) and Google Cloud | Discover and rotate cloud access keys and accounts. |
| Existing infrastructure | Works with the directories, mail, SIEM, and ticketing systems already in place. |
| REST API | Full JSON REST API with an OpenAPI description. |
| Identity Governance and Administration (IGA) | Account lifecycle and periodic access review for kit accounts. Governance across other applications is planned. |
| Multi-Factor Authentication (MFA), including OATH TOTP and YubiKey | Time-based one-time passwords, FIDO2 security keys including YubiKey, and RADIUS. |
| Okta, SAML, and single sign-on | SAML 2.0 and OpenID Connect sign-in with Okta, Microsoft Entra ID, and others. |
| RADIUS | RADIUS second factor. |
| ServiceNow, Jira, and other ticketing systems | Require a valid ticket before access, and open tickets from events. |
| SIEM, syslog, and Splunk | Syslog (RFC 5424) and direct delivery to Splunk, Microsoft Sentinel, Datadog, Amazon CloudWatch, and Google Cloud Logging. |
| Hardware Security Module (HSM) and key management services | Keys in software, a PKCS#11 HSM, or a cloud key management service. |
| Incident management | Incident detection, notices, and evidence. |
| Native logon page that bypasses single sign-on when needed | Local logon stays available for break-glass and administrators. |
| Custom ticketing integration | Webhooks and the REST API. |
| Vulnerability scanner integration | Supply credentials to scanners and import findings. |
| Customer Relationship Management (CRM) integration | Manage credentials for CRM platforms. |
Password management
| Requirement | How AIC meets it |
|---|---|
| Automated rotation on a schedule or a trigger, with complexity rules | Rotate on a schedule, after check-in, or on demand, under per-policy complexity rules. |
| Check-out and check-in | Exclusive check-out with a time limit and forced check-in. |
| Granular password policies | Length, character sets, history, age, and rotation per account group. |
| MFA before access | Required second factor before reveal or check-out. |
| Heartbeat to detect out-of-band changes | Regularly verify each stored password still works, and alert when it does not. |
| CSV and XML import and export | Bulk import and export of accounts. |
| Just-in-time group membership on check-out | Add to a group on check-out and remove on check-in. |
| One-time passwords, rotated on check-in | Each check-out gets a password that is changed on return. |
| Encryption, hiding, and vaulting | AES-256 encryption at rest, hidden by default, manual entries supported. |
| Secret policy on stored credentials | Policies apply to every stored credential type. |
| Web password vaulting | Store and launch website credentials. |
| File attachments | Attach files to vault entries. |
| Folders and permissions | Folders with inherited permissions. |
| Personal password and file vaulting | Each person has a private vault for passwords and files. |
Secret workflow
| Requirement | How AIC meets it |
|---|---|
| Out-of-the-box policies | Default policies ship and can be cloned. |
| Force check-in and remove a lock | Administrators release a checked-out credential. |
| Role-Based Access Control (RBAC) | Permissions by role on every admin and enclave route. |
| Attribute-Based Access Control (ABAC) | Grant access from attributes of the person, the target, and the request. |
| Exclusion rules | Exclude accounts and systems from management or discovery. |
| Double lock and compartments | Separate permissions and second approval for sensitive groups. |
| Require a comment on access | A reason is required and stored with the record. |
| Request and approval workflow | Request, approve, deny, and time-bound grants with notifications. |
| Role inheritance | Roles assigned to groups and inherited by members. |
Security and compliance
| Requirement | How AIC meets it |
|---|---|
| Create SSH certificates | Issue short-lived SSH certificates for sessions. |
| AES-256 encryption at rest | Every stored secret is encrypted with AES-256-GCM. |
| Encryption in transit with Transport Layer Security (TLS) 1.2 or later | TLS 1.2 and 1.3 only. |
| Federal Information Processing Standards (FIPS) cryptography | AWS-LC, which holds a FIPS 140-3 certificate, on server cryptographic paths. FIPS 140-3 replaces FIPS 140-2. |
| HIPAA, PCI, and SOX audit support | Access control, rotation, recording, and audit reports that those audits ask for. Whether an organization complies is decided by its auditors. |
| Conditional policies by location and time | Allow or deny access by time window and by location. |
| Geolocation rules | Block or flag sign-ins from listed countries. |
| Behavior analytics | Detection rules alert on unusual privileged activity. Machine-learning analytics are planned. |
Session launching and monitoring
| Requirement | How AIC meets it |
|---|---|
| Central management console | One web console. |
| No third-party tools needed for sessions | SSH, RDP, and VNC run in the browser. |
| Log tracing | Every session links to its audit events. |
| RDP and SSH proxying, including PuTTY and native clients | Brokered RDP and SSH with credentials injected. |
| Automatic RDP and SSH launch on shared-account access | One click opens a session with the credential injected. |
| Real-time monitoring, pause, and kill | Watch a live session, pause it, or end it. |
| Session recording and archive | Recordings sealed at rest, replayed in the console, and archived under a retention policy. |
| SSH key management | Discover, rotate, and push SSH keys. |
| Concurrent sessions | Several sessions at once, with limits per policy. |
| HTTPS | All console and API traffic over HTTPS. |
| Web password launching with transparent sign-in | Open a website with the stored credential filled in. |
| Mobile device policies by group | Apply mobile access rules per group. |
| Alerts on critical events | Alert rules on checkout, reveal, failed rotation, and policy violations. |
| Search inside recorded sessions | Search typed commands and on-screen text in recordings. |
| Keystroke logging | Typed commands are captured with the recording. |
| Block critical commands, with allow and deny lists | Dangerous commands are blocked as they are typed in SSH sessions, with allow and deny lists. |
| Session timeout | Idle and absolute timeouts. |
| Web password session recording | Web sessions launched from the vault are recorded. |
| Unix privilege elevation | Controlled sudo elevation on Unix and Linux. |
Web API, SDK, and scripting
| Requirement | How AIC meets it |
|---|---|
| Bash, PowerShell, and SQL scripts | Run scripts before and after rotation, and use them to change passwords on custom platforms. |
| Full JSON REST API for programmatic credential retrieval | REST API with an OpenAPI description and scoped tokens. |
| PowerShell password changes | Change passwords with PowerShell. |
| Software Development Kit (SDK) for applications | Applications fetch credentials with no person involved. |
| SSH dependencies such as su and sudo | Rotation and sessions handle su and sudo steps. |
Ease of use
| Factor | How AIC meets it |
|---|---|
| One product with every feature | PIM, PAM, PUM, discovery, governance, and audit evidence in one product with one roster and one audit trail. |
| Onboarding | Guided setup, discovery first, and free training. |
| License model | One quote for one platform. Partners can sell and support it. |
| Support after implementation | Partner and customer support with escalation to engineering. |
| Implementation | A standard, pre-configured kit with the same design for every customer. |
And more: capabilities beyond the checklist
| Capability | What it does |
|---|---|
| Credential propagation and blast radius | Push a new password to every place that uses it, and report how far each shared credential reaches. |
| Browser automation | Change passwords on devices managed only through a web page. |
| Endpoint privilege elevation | Elevate on Windows, Apple macOS, and Linux with one-time codes, challenge and response, or signed grants. |
| Configuration compliance | Check systems against a baseline configuration and report configuration drift. |
| Current State Compliance and the Assessment Binder | Findings with rescan, and an auditor package built from live records. |
| Training and attestation | Assign training, collect signed attestations, and report completion. |
| Air-gapped operation | The full product runs with no internet connection. |
| Operational Technology (OT) | Inventory and credential management for industrial devices. |
| Vendor remote access without a VPN | Browser sessions for outside vendors with approval and recording. |
| Mainframe terminals | Telnet scripts for terminal-based systems. |
| Service account governance | Ownership and periodic review of service accounts. |
| Identity Governance and Administration | Account lifecycle and access review for kit accounts. |
| DevOps secrets for pipelines and Kubernetes | Deliver secrets to build pipelines and containers. |
| Cloud Infrastructure Entitlement Management (CIEM) | Analyze cloud permissions and entitlements. |
| Certificate lifecycle management | Discover, renew, and replace TLS certificates. |
| Just-in-time network access | Open network paths only for the length of an approved session. |
| Robotic process automation (RPA) bot credentials | Supply credentials to software robots. |
Frequently asked questions
Does AIC cover every category in a privileged access RFP?
Yes. Each of the eleven categories is listed above, row by row, with its availability.
Are these separate products?
No. Every row above is part of one product with one roster, one policy engine, and one audit trail.
Does this checklist mean an organization passes an audit?
No. The product provides the controls and the records. The organization's auditors decide whether a requirement is satisfied.
Related pages
- AIC capabilities
- Privileged Identity Management
- Privileged User Management
- Logging and SIEM
- Security
Next step
Send us your RFP checklist and we will return it filled in, row by row. Request a demo.