Vaulting everything you discover isn't a strategy for reducing risk, because the right action depends on what the account actually does. Within PAM, discovery processes typically produce a list of accounts, and the instinct is to vault all of it. But is that the optimal decision, either for the end user or for security?
Understanding the risk an account carries is the first step in choosing the correct action. An account holding broad standing rights that authenticates twice a year warrants different treatment from one holding identical rights and running continuously against production. The same entitlement can justify completely different decisions depending on use. Without the context of the account's activity, you can't make the right posture, configuration and access rights decisions.
Five actions to take, and only one of them is vaulting
A discovered account can be vaulted and managed, converted to just-in-time credentials so the standing privilege disappears, right-sized to the rights it actually exercises, deprovisioned because nothing depends on it, or explicitly accepted with a named owner and a review date.
Palo Alto Networks' 2026 Identity Security Landscape report found that on average only 39% of privileged access is managed through just-in-time or zero standing privilege. The rest is standing access. Putting a vault around standing access contains the risk, but it doesn't remove it.
The decision needs behavioral context
Entitlement data on its own can't route an account to the right ending, because entitlements only describe what could be done. Authentication events describe what is being done, and that's usually what decides the action.
Take a service account with local admin rights on sixty Windows servers. The entitlement record says high privilege, so the default answer is to vault it. The authentication history tells you which kind of account you're actually looking at.
One of them authenticates every night between 1:00 and 1:20, never interactively. Nothing about that account needs session management or a checkout workflow. It needs scheduled rotation coordinated with the two services that depend on it, and a named owner who knows those services exist.
Another account, same rights and the same naming convention, shows interactive logons from thirty-four workstations across three regions at all hours, along with a run of failed logins every time somebody's saved password goes stale. This is clearly a shared human credential doing the job of a service account, and it needs a vault, session recording, and a plan to split it into individual accounts before anyone signs off on another review.
Same entitlements, opposite decisions. The only thing separating them was the authentication record.
Routing thousands of accounts is an analytical job
Nobody completes this in a spreadsheet, because it means asking the same data the same questions over and over. You need to be able to ask things like: show me every privileged account added to an admin group in the last thirty days, or show me privileged accounts that haven't logged in for a year. From there you can classify accounts, tag the ones that can be deprovisioned, and mark the break-glass accounts so nobody touches them by mistake.
Notice that both of those questions are about history, not current state. Your directory can tell you who is in the admin group today. It usually can't tell you who was added last month, or when this account last authenticated, or what changed between the last two reviews. That gap is why the analysis keeps falling back on people's memory.
Where this leaves you
Hydden keeps a continuous record of accounts, their entitlements, and the activity against them, so the questions above have somewhere to be answered. That record is what makes it possible to automatically route accounts to their proper disposition. Each decision comes out of evidence you can show someone, and it can be made again when the account changes, rather than holding until the next time somebody has the time to look during a formal access review.
Hydden doesn't replace your vault. Accounts get routed into the PAM you already run, and the same record is what your access reviews, provisioning and deprovisioning work from.
Vaulting is still the right answer for plenty of accounts. It just shouldn't be the only answer available.
Frequently asked questions
Why shouldn't every privileged account you discover be vaulted?
A vault contains risk without removing it, and vaulting is only one of five actions available. An account holding broad standing rights that authenticates twice a year warrants different treatment from one holding identical rights and running continuously against production. The right action depends on what the account actually does.
What are the options besides vaulting a privileged account?
There are five. Vault and manage it, convert it to just-in-time credentials so the standing privilege disappears, right-size it to the rights it actually exercises, deprovision it because nothing depends on it, or explicitly accept it with a named owner and a review date.
Why is entitlement data alone not enough to decide what to do with an account?
Entitlements describe what could be done with an account. Authentication events describe what is being done, and that is usually what decides the action. Two accounts with the same rights and the same naming convention can warrant opposite decisions, and the only thing separating them is the authentication record.
How does activity data change the decision for a privileged service account?
An account that authenticates in the same twenty-minute window every night and never interactively needs scheduled rotation coordinated with the services that depend on it, plus a named owner, rather than session management or a checkout workflow. The same rights combined with interactive logons from dozens of workstations at all hours point to a shared human credential, which needs a vault, session recording, and a plan to split it into individual accounts.
Why can't privileged account disposition be worked out in a spreadsheet?
Routing thousands of accounts means asking the same data the same questions repeatedly, such as which privileged accounts joined an admin group in the last thirty days, or which have not authenticated in a year. Both are questions about history rather than current state, and a directory generally cannot answer them, which is why the analysis keeps falling back on people's memory.
Does Hydden replace your PAM vault?
No. Accounts get routed into the PAM you already run, and the same record is what your access reviews, provisioning and deprovisioning work from. Hydden keeps the continuous record of accounts, entitlements and activity that makes each disposition decision evidence-based and repeatable when the account changes.

