Privileged access requirements checklist: every RFP category, row by row

Regulated buyers evaluate privileged access products with a long Request for Proposal (RFP) checklist. The checklist below follows the eleven categories those buyers use: auditing and reporting, deployment and support, discovery, disaster recovery and high availability, integrations, password management, secret workflow, security and compliance, session launching and monitoring, the Web API and scripting, and ease of use. Each row states how Analog Informatics Corporation (AIC) meets the requirement and whether it is available now.

AIC is one product. Privileged Identity Management (PIM) - vaulting, rotating, and propagating credentials - Privileged Access Management (PAM) - brokered and recorded sessions - and Privileged User Management (PUM) - endpoint privilege elevation and delegation - share one roster, one policy engine, and one audit trail. The rows below are not stitched together from separate products.

Eleven labeled tiles in a grid - auditing, deployment, discovery, recovery, integrations, passwords, workflow, security, sessions, API, ease of use - all inside one outer box labeled AIC.
The eleven categories a regulated buyer scores all map to one AIC product with one roster and one audit trail.

Auditing and reporting

Requirement How AIC meets it
Account permission reports Report who can see, check out, or use each vaulted account, and through which role or set.
Trace every administrator and user action to a person and a time Every action is recorded with the named person, the target, the outcome, and the server time. Windows Event Log and syslog carry the same record.
Out-of-the-box and on-demand reports for owners Built-in reports for accounts, rotation, sessions, access, and audit events, run on demand.
Automated report queries Saved report queries run on a schedule and deliver results.
Log creation, storage, analytics, and alerting Audit log with search and filters, retention and archive, and alert rules. Forward to any Security Information and Event Management (SIEM) collector.
Email notifications Email through the organization's mail server, including Microsoft 365 and Outlook, with message templates.
Event subscriptions and alerts Subscribe people and groups to events and reports.
Inactive-account reporting Report accounts with no recent logon, on demand or on a schedule.
Password history Every prior password value is kept, encrypted, with who changed it and when.
Scheduled reports Reports run on a schedule and are emailed or saved.
Security assessment reporting Current State Compliance - the admin ledger of control-oriented findings with rescan - and the Assessment Binder export.
Self-monitoring, health check, and repair The server checks its own services, storage, and connections, reports health, and repairs shipped reference data that is missing after an upgrade.
User audit report All actions for one person over a date range.
Agentless auditor tools Read-only auditor role in the console and the Assessment Binder. No software installed for the auditor.
Custom reports Build reports from fields, filters, and grouping, and save them.
External auditing tool integration Syslog (RFC 5424), Windows Event Log, and the REST API feed outside audit tools.
Ad-hoc user reports Filter any report by person, system, or time and export it.
Dual control (four eyes) A second person must approve before a credential is released.

Deployment and support

Requirement How AIC meets it
Data segregation between customers Each customer runs in its own instance or enclave with its own database and keys.
Same features in the cloud and on premises One server build runs in the cloud, on premises, and air-gapped.
Network zone segmentation Engines and agents run inside each zone and connect out to the server.
Centralized administration One web console for every module.
On-premises deployment Windows and Linux server installers.
On-site engines to reach untrusted networks Agents, discovery engines, and session gateways run in the remote network or demilitarized zone (DMZ).
Password masking at logon Passwords are injected into sessions and never shown unless a person with permission reveals them.
Cloud (SaaS) deployment Hosted on Microsoft Azure. Other clouds are listed on the deployment page.
Selective, targeted discovery refresh Re-run discovery for one system, one set, or one account type.
Support for current Payment Card Industry (PCI) controls Rotation, access review, session recording, and audit reports that PCI Data Security Standard audits ask for.
IP address restrictions Limit console and API access to listed networks.
Notice before a hosted upgrade Release notes and notice before hosted upgrades.
Pre-upgrade testing site A staging site to test an upgrade before production.
Optional agent Agentless management over WinRM and SSH, or the Agent where an agent is preferred.
24/7 support with a service level agreement Partner and customer support with escalation to engineering. A 24/7 service level agreement is planned.

Discovery

Requirement How AIC meets it
Active Directory synchronization Read users, groups, and computers from Active Directory over verified LDAPS.
Automatic discovery of privileged accounts Scan systems for local and domain accounts and privileged group membership.
Windows, Unix and Linux, LDAP, and Active Directory accounts Discovered and managed.
Database accounts Discovered and managed on the common database platforms.
Network device and appliance accounts Discovered and managed over SSH, Telnet scripts, and browser automation.
Discovery rules that auto-manage credentials Rules bring matching accounts under management automatically.
Service accounts Find every service, scheduled task, application pool, COM+ application, and configuration file that uses an account, and update each one when the password changes.
Pruning obsolete accounts Remove accounts that no longer exist on the target.
Decommission devices based on Active Directory status Retire systems that are disabled or removed in Active Directory.
Discover SSH certificates on targets Find SSH certificates on managed systems.
Custom account types Define custom platforms with scripts, browser automation, or the API, managed or manual.

Disaster recovery and high availability

Requirement How AIC meets it
Automatic backups Scheduled, encrypted database and configuration backups.
Cloud architecture Runs as a hosted service on Microsoft Azure.
On-premises recovery copy of the cloud service Export an encrypted backup to the organization's own storage.
Break-glass emergency access Sealed emergency accounts with recorded use and forced rotation afterward.
Load balancing Spread console and API load across several servers.
High availability and clustering Run several servers so service continues if one fails.
Geo-replication for recovery Keep a live copy in a second region.

Integrations

Requirement How AIC meets it
Active Directory, Microsoft Entra ID, and LDAP Directory sign-in, discovery, and group sync.
Amazon Web Services (AWS) and Google Cloud Discover and rotate cloud access keys and accounts.
Existing infrastructure Works with the directories, mail, SIEM, and ticketing systems already in place.
REST API Full JSON REST API with an OpenAPI description.
Identity Governance and Administration (IGA) Account lifecycle and periodic access review for kit accounts. Governance across other applications is planned.
Multi-Factor Authentication (MFA), including OATH TOTP and YubiKey Time-based one-time passwords, FIDO2 security keys including YubiKey, and RADIUS.
Okta, SAML, and single sign-on SAML 2.0 and OpenID Connect sign-in with Okta, Microsoft Entra ID, and others.
RADIUS RADIUS second factor.
ServiceNow, Jira, and other ticketing systems Require a valid ticket before access, and open tickets from events.
SIEM, syslog, and Splunk Syslog (RFC 5424) and direct delivery to Splunk, Microsoft Sentinel, Datadog, Amazon CloudWatch, and Google Cloud Logging.
Hardware Security Module (HSM) and key management services Keys in software, a PKCS#11 HSM, or a cloud key management service.
Incident management Incident detection, notices, and evidence.
Native logon page that bypasses single sign-on when needed Local logon stays available for break-glass and administrators.
Custom ticketing integration Webhooks and the REST API.
Vulnerability scanner integration Supply credentials to scanners and import findings.
Customer Relationship Management (CRM) integration Manage credentials for CRM platforms.

Password management

Requirement How AIC meets it
Automated rotation on a schedule or a trigger, with complexity rules Rotate on a schedule, after check-in, or on demand, under per-policy complexity rules.
Check-out and check-in Exclusive check-out with a time limit and forced check-in.
Granular password policies Length, character sets, history, age, and rotation per account group.
MFA before access Required second factor before reveal or check-out.
Heartbeat to detect out-of-band changes Regularly verify each stored password still works, and alert when it does not.
CSV and XML import and export Bulk import and export of accounts.
Just-in-time group membership on check-out Add to a group on check-out and remove on check-in.
One-time passwords, rotated on check-in Each check-out gets a password that is changed on return.
Encryption, hiding, and vaulting AES-256 encryption at rest, hidden by default, manual entries supported.
Secret policy on stored credentials Policies apply to every stored credential type.
Web password vaulting Store and launch website credentials.
File attachments Attach files to vault entries.
Folders and permissions Folders with inherited permissions.
Personal password and file vaulting Each person has a private vault for passwords and files.

Secret workflow

Requirement How AIC meets it
Out-of-the-box policies Default policies ship and can be cloned.
Force check-in and remove a lock Administrators release a checked-out credential.
Role-Based Access Control (RBAC) Permissions by role on every admin and enclave route.
Attribute-Based Access Control (ABAC) Grant access from attributes of the person, the target, and the request.
Exclusion rules Exclude accounts and systems from management or discovery.
Double lock and compartments Separate permissions and second approval for sensitive groups.
Require a comment on access A reason is required and stored with the record.
Request and approval workflow Request, approve, deny, and time-bound grants with notifications.
Role inheritance Roles assigned to groups and inherited by members.

Security and compliance

Requirement How AIC meets it
Create SSH certificates Issue short-lived SSH certificates for sessions.
AES-256 encryption at rest Every stored secret is encrypted with AES-256-GCM.
Encryption in transit with Transport Layer Security (TLS) 1.2 or later TLS 1.2 and 1.3 only.
Federal Information Processing Standards (FIPS) cryptography AWS-LC, which holds a FIPS 140-3 certificate, on server cryptographic paths. FIPS 140-3 replaces FIPS 140-2.
HIPAA, PCI, and SOX audit support Access control, rotation, recording, and audit reports that those audits ask for. Whether an organization complies is decided by its auditors.
Conditional policies by location and time Allow or deny access by time window and by location.
Geolocation rules Block or flag sign-ins from listed countries.
Behavior analytics Detection rules alert on unusual privileged activity. Machine-learning analytics are planned.

Session launching and monitoring

Requirement How AIC meets it
Central management console One web console.
No third-party tools needed for sessions SSH, RDP, and VNC run in the browser.
Log tracing Every session links to its audit events.
RDP and SSH proxying, including PuTTY and native clients Brokered RDP and SSH with credentials injected.
Automatic RDP and SSH launch on shared-account access One click opens a session with the credential injected.
Real-time monitoring, pause, and kill Watch a live session, pause it, or end it.
Session recording and archive Recordings sealed at rest, replayed in the console, and archived under a retention policy.
SSH key management Discover, rotate, and push SSH keys.
Concurrent sessions Several sessions at once, with limits per policy.
HTTPS All console and API traffic over HTTPS.
Web password launching with transparent sign-in Open a website with the stored credential filled in.
Mobile device policies by group Apply mobile access rules per group.
Alerts on critical events Alert rules on checkout, reveal, failed rotation, and policy violations.
Search inside recorded sessions Search typed commands and on-screen text in recordings.
Keystroke logging Typed commands are captured with the recording.
Block critical commands, with allow and deny lists Dangerous commands are blocked as they are typed in SSH sessions, with allow and deny lists.
Session timeout Idle and absolute timeouts.
Web password session recording Web sessions launched from the vault are recorded.
Unix privilege elevation Controlled sudo elevation on Unix and Linux.

Web API, SDK, and scripting

Requirement How AIC meets it
Bash, PowerShell, and SQL scripts Run scripts before and after rotation, and use them to change passwords on custom platforms.
Full JSON REST API for programmatic credential retrieval REST API with an OpenAPI description and scoped tokens.
PowerShell password changes Change passwords with PowerShell.
Software Development Kit (SDK) for applications Applications fetch credentials with no person involved.
SSH dependencies such as su and sudo Rotation and sessions handle su and sudo steps.

Ease of use

Factor How AIC meets it
One product with every feature PIM, PAM, PUM, discovery, governance, and audit evidence in one product with one roster and one audit trail.
Onboarding Guided setup, discovery first, and free training.
License model One quote for one platform. Partners can sell and support it.
Support after implementation Partner and customer support with escalation to engineering.
Implementation A standard, pre-configured kit with the same design for every customer.

And more: capabilities beyond the checklist

Capability What it does
Credential propagation and blast radius Push a new password to every place that uses it, and report how far each shared credential reaches.
Browser automation Change passwords on devices managed only through a web page.
Endpoint privilege elevation Elevate on Windows, Apple macOS, and Linux with one-time codes, challenge and response, or signed grants.
Configuration compliance Check systems against a baseline configuration and report configuration drift.
Current State Compliance and the Assessment Binder Findings with rescan, and an auditor package built from live records.
Training and attestation Assign training, collect signed attestations, and report completion.
Air-gapped operation The full product runs with no internet connection.
Operational Technology (OT) Inventory and credential management for industrial devices.
Vendor remote access without a VPN Browser sessions for outside vendors with approval and recording.
Mainframe terminals Telnet scripts for terminal-based systems.
Service account governance Ownership and periodic review of service accounts.
Identity Governance and Administration Account lifecycle and access review for kit accounts.
DevOps secrets for pipelines and Kubernetes Deliver secrets to build pipelines and containers.
Cloud Infrastructure Entitlement Management (CIEM) Analyze cloud permissions and entitlements.
Certificate lifecycle management Discover, renew, and replace TLS certificates.
Just-in-time network access Open network paths only for the length of an approved session.
Robotic process automation (RPA) bot credentials Supply credentials to software robots.

Frequently asked questions

Does AIC cover every category in a privileged access RFP?

Yes. Each of the eleven categories is listed above, row by row, with its availability.

Are these separate products?

No. Every row above is part of one product with one roster, one policy engine, and one audit trail.

Does this checklist mean an organization passes an audit?

No. The product provides the controls and the records. The organization's auditors decide whether a requirement is satisfied.

Related pages

Next step

Send us your RFP checklist and we will return it filled in, row by row. Request a demo.