Privileged access management skipped everyone between 50 and 500 engineers
Disclosure: I work on Tessera, which is one of the tools in the gap I am describing. Ask a fifty-person engineering organisation how they control production access and you will hear the same answer with small variations: a bastion host, SSH keys distributed by configuration management, a shared kubeconfig somewhere, and a spreadsheet or a Notion page that is out of date. Nobody chose that. It is…
In the middle ground between 50 and 500 engineers, privileged access management (PAM) tools have become unaffordable and ineffective. Traditional PAM solutions, designed for large enterprises with thousands of administrators and regulated industries, are priced per protected resource, which leads to escalating costs for growing teams. The realistic option for these mid-sized organisations is to build their own PAM solution, but this is often unrealistic due to the time and resources required.
Three recent shifts have enabled a viable alternative: self-hosting has become a feasible option, deployment no longer necessitates professional services, and pricing models have transitioned to per-seat pricing. As a result, organisations within this size bracket are now considering PAM tools that offer session-level control, audit evidence, and are priced accordingly.
Tessera, a self-hosted access broker for SSH, Kubernetes, databases, and RDP, is one such solution. With a free tier available for a single administrator, Tessera aligns with the pricing model that fits these organisations. Other similar tools include Teleport and Boundary, both of which have free tiers and can be deployed quickly without requiring any changes to your targets or additional installations on your infrastructure.
These tools can provide the necessary session-level control and audit evidence required to satisfy auditors and customers without incurring prohibitive costs. Therefore, it is recommended to implement such a solution before an audit to ensure evidence covers the audit period.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.