PAM secured the endpoint; privilege moved on. Work through these 21 controls to find out where standing access is accumulating in your cloud, SaaS, and AI estate — and how to shut it down without slowing anyone.
For twenty years, privileged access management (PAM) was an endpoint discipline: vault the credentials, strip local admin rights, broker and record the sessions. It worked because privilege lived where the controls did.
Today, infrastructure runs in AWS, Azure, and Google Cloud, crown-jewel data sits in SaaS, and a fast-growing fleet of service accounts, pipelines, and AI agents holds always-on permissions no vault has ever seen.
Attackers have noticed: they no longer break in, they log in — and inherit every standing entitlement that identity has accumulated.
Use the checklist below to audit how far your privilege programme actually extends.
It runs in five phases, from the endpoint baseline you probably already have to the just-in-time (JIT) model that eliminates standing access entirely.
Treat every unchecked box as a finding: give it an owner, a deadline, and a metric. The phases are sequential by design discovery before right-sizing, right-sizing before JIT but nothing stops you piloting JIT on one high-risk system while the wider inventory work runs.
WEBINAR SPOTLIGHT :
Beyond the Endpoint: Where Privilege Went Next, and How Entitle Follows
BeyondTrust's APJ Tech Talk Tuesday session walks this exact journey live, with Entitle discovering, right-sizing, and granting cloud access just-in-time. Reserve your seat →
The endpoint threat model hasn’t gone away — it has been joined by a much larger one. Recent industry research shows just how far standing privilege has spread beyond anything a traditional vault was built to see:
These aren’t abstract risks. IBM’s 2026 Cost of a Data Breach Report, based on 602 breached organisations worldwide, puts the global average breach at a record $4.99 million, up 12% in a year and the industries carrying the most standing entitlement pay the most for it:
Source: IBM Cost of a Data Breach Report 2026 (29 Jul 2026)
Two of 2026’s highest-profile incidents show exactly how standing access turns into headlines:
Source: Trend Micro, “The Vercel Breach: OAuth Supply Chain Attack”
Source: Cyber Security News, “Salesloft Takes Drift Offline After OAuth Token Theft”
Neither breach needed a zero-day. Vercel and Salesloft/Drift both trace back to the same root cause: a grant that made sense on the day it was issued and was never revisited, reviewed, or time-boxed after that.
Standing access doesn’t fail loudly — it just waits for the day someone else finds it first. The five countermeasures below are what close that gap, and they only work in order:
Work through the checklist below phase by phase — each one gives you the specific controls behind the summary above.
None of the cloud work matters if the original battleground is still open. Confirm the fundamentals first:
You cannot right-size what you cannot see. This phase is pure discovery — and it is where most programmes find their blind spot:
Figure 1: Privilege has migrated from the vault-governed endpoint into IaaS entitlements, SaaS admin models, and non-human and AI identities — where it sits as unmanaged standing access.
Discovery becomes risk reduction only when dormant privilege starts disappearing:
Wondering how many of these boxes your organisation could tick today? The upcoming BeyondTrust Tech Talk includes a practical maturity assessment across the endpoint-to-cloud privilege spectrum — register here.
Prefer to talk it through with someone first? Book 20 minutes with an Entitle specialist →
The endpoint lesson, applied to the cloud: do not manage standing privilege better remove it, and grant access only when needed, for only as long as needed.
That model is zero standing privileges (ZSP), and it lives or dies on workflow. More than two-thirds of security teams already say they plan to deploy JIT access for privileged users — the gap is rarely intent, it’s the workflow to run it at scale:
Figure 2: The just-in-time access lifecycle — every grant is requested in context, time-boxed at birth, revoked automatically, and evidenced end to end.
Three questions tell you whether the programme is real:
Score yourself honestly. Most organisations clear Phase 1 and stall in Phase 2 — not for lack of tooling, but because visibility and workflow were never extended beyond the endpoint.
The encouraging news: the second half of the journey moves faster than the first, because once entitlements are discovered and usage is measured, converting standing grants into just-in-time access is largely an automation exercise.
Privilege has left the endpoint for good; the discipline that secured it does not have to stay behind.
Where teams are putting this into practice today — by sector, and cross-industry:
FINANCIAL SERVICES : Segregation-of-duties enforcement — time-boxed access to core banking and trading systems so no single standing grant crosses an audit boundary.
HEALTHCARE : Need-to-treat EHR and PHI access — clinicians and support staff get record access for the duration of care, with the time-stamped audit trail HIPAA reviewers expect.
TECHNOLOGY & SAAS : JIT production access — engineers request from Slack, Teams, or the CLI; access is provisioned natively with an expiry attached.
RETAIL & E-COMMERCE: Narrow, expiring access to PCI-scoped systems — seasonal staff and contractors get payment-system access that disappears the moment the shift or contract ends.
ENERGY & CRITICAL INFRASTRUCTURE : Time-boxed vendor and OT remote access — third-party maintenance access is revoked automatically the moment the work order closes.
CROSS-INDUSTRY
SEE IT LIVE, OR TALK IT THROUGH
Beyond the Endpoint: Where Privilege Went Next, and How Entitle Follows
A practical APJ Tech Talk Tuesday session from BeyondTrust showing every phase of this checklist in action discovering, right-sizing, and granting cloud access just-in-time with Entitle on the Pathfinder platform. Built for security and IAM teams with established PAM programmes, organisations midway through their identity security journey, and cloud and DevOps teams eliminating standing access without slowing delivery.
1. Register free — Reserve your seat →
2. Talk to an Entitle expert — skip the slides and walk through your own environment 1:1. Request a demo →
Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…