Cross-stack identity risk under control
CyberArk PAM lifecycle, governed
Discover our mission and values
Our social and environmental impact
Join us
Our strategic alliances
All our news
Our next meetings
Discover our success stories
Managing between 10,000 and more than a million privileged accounts is business as usual for many large CyberArk Idira customers. But having accounts sitting in one or several vaults doesn’t mean knowing exactly what’s happening inside them. How many accounts actually exist? Who has access, and through which channel? Which accounts are orphaned, outdated, or poorly documented?
Without automated, continuous discovery, these questions stay unanswered, and every regulatory audit or control (DORA, NIS2, ISO 27001) turns into a manual, time-consuming, error-prone exercise.
A CyberArk Idira vault that grows without a dedicated governance tool progressively accumulates gaps that become harder to spot over time. On multi-vault environments (Privilege Cloud, on-premise, or both), with tens of thousands of accounts inherited from years of onboarding, some anomalies easily go unnoticed.
One example observed on a demo environment: 138 issues detected across accounts, including 34 accounts with no usable username,often inherited from legacy PACLI scripts. This kind of gap usually stays invisible until an audit or in-depth review brings it to light.
As soon as Ignimission Protec is installed, it connects to your CyberArk Idira environment, one or several vaults, Privilege Cloud as well as on-premise, along with your other identity and infrastructure sources: Active Directory, CMDB, databases, network devices. The platform then starts discovering privileged accounts and assets automatically, with no lengthy integration project required.
This discovery feeds the Health Check, a standard dashboard that gives:
This foundation lets PAM management run on live data instead of one-off extractions.
Beyond aggregated indicators, Protec lets you drill down to the individual account: full metadata, who has access and through which channel, group or direct access, and with what level of permission. Account activity is consolidated in the same view, for full traceability without switching tools.
The Safe Members view completes this picture, showing at a glance who has access to a given safe, whether nominative, direct, or through a group, a useful reference point for access reviews or recertification campaigns, whether in a PAM-focused approach or a broader IGA strategy. Standard views can also be adapted: by applying filters and rules and saving them as a new view, or by using the drag-and-drop studio to build fully personalized dashboards.
Discovered data can be filtered by team, region, or application scope, SAP, ServiceNow, or any other sensitive system, through the Business Service module. A SAP Finance team lead can view their own accounts, issues, and risk score without navigating the entire CyberArk repository. The CISO, meanwhile, keeps a consolidated view of critical risks across the whole organization.
That distinction is what separates a generic PAM reporting tool from a genuine privileged access governance platform: every stakeholder, CISO, auditor, business owner, IAM/IGA team, sees exactly what concerns them, with no extra reformatting.
Data remains exportable to Excel and accessible via API, and Protec’s low-code / no-code architecture lets you build further dashboards by drag-and-drop, independent of any development cycle.
Remediation, recertification, and audit response all rest on the same prerequisite: a reliable, up-to-date view of the CyberArk perimeter. Automated discovery isn’t a standalone feature, it’s the starting point of a consistent CyberArk, IGA, and PAM governance strategy over time.
That’s the role of the Discovery module in Ignimission Protec: connect, map, and oversee your CyberArk ecosystem, whatever its size or number of vaults.
Do you want a precise view of your CyberArk environment? Request a demo of Ignimission Protec to see discovery run on your own perimeter.