PAM certification, anomaly detection,
ServiceNow-bridged.
30 synthetic CyberArk PAM safes · 6 detected anomaly patterns · ServiceNow access-review ticket sync · ed25519-signed hash-chained audit. Buyer-facing operator surface, browser-only, no live data.
Safes overview — Continental Banking & Trust
30 synthetic CyberArk PAM safes across infra, SaaS, identity, and secrets-management tiers. 9 currently overdue (3 at crit-severity 30+ days). Quarterly-cert clock starts at safe creation; ServiceNow tickets auto-open at T-7d.
| Safe | Classification | Owner | Status | Members | SNOW Tix |
|---|---|---|---|---|---|
| PROD-DB-Oracle | Database / Oracle | Sandra Volkov | Overdue 14d | 67 | 2 SNOW |
| PROD-DB-Postgres | Database / Postgres | Jamal Reeves | In review | 102 | 7 SNOW |
| PROD-Linux-Sudoers | Linux / sudoers | Priya Anand | Current | 41 | — |
| PROD-Windows-DA | Windows / Domain Admin | Erin Kowalski | Overdue 3d | 12 | — |
| PROD-K8s-ClusterAdmin | K8s / cluster-admin | Marcus Liu | In review | 8 | 4 SNOW |
| PROD-AWS-OrgRoot | AWS / Organization | (unassigned) | Overdue 41d | 3 | 1 SNOW |
| PROD-Azure-GlobalAdmin | Azure / Global Admin | Sandra Volkov | In review | 11 | — |
| PROD-GCP-OrgOwner | GCP / Org Owner | Marcus Liu | Current | 5 | — |
| STAGE-DB-MySQL | Database / MySQL | Jamal Reeves | Overdue 56d | 89 | 18 SNOW |
| STAGE-AppServer-Tomcat | App / Tomcat | Erin Kowalski | Current | 34 | — |
| DEV-Jenkins-Build | CI / Jenkins | Priya Anand | In review | 67 | 3 SNOW |
| DEV-SourceControl-GitLab | CI / GitLab | Priya Anand | Current | 92 | — |
| PROD-Cassandra-Ring | Database / Cassandra | Sandra Volkov | Overdue 19d | 28 | 6 SNOW |
| PROD-Salesforce-Admin | SaaS / Salesforce | Erin Kowalski | In review | 19 | 1 SNOW |
| PROD-Workday-Tenant | SaaS / Workday | (unassigned) | Overdue 84d | 11 | 22 SNOW |
| PROD-NetworkOps-Bastion | Network / Bastion | Marcus Liu | In review | 7 | — |
| PROD-Splunk-Index-Admin | Observability / Splunk | Priya Anand | Current | 23 | — |
| PROD-Datadog-Org-Admin | Observability / Datadog | Sandra Volkov | In review | 15 | 4 SNOW |
| PROD-Snowflake-AccountAdmin | Data / Snowflake | Marcus Liu | Current | 38 | — |
| PROD-Vault-Root | Secrets / HashiCorp Vault | Jamal Reeves | Overdue 38d | 6 | 11 SNOW |
| STAGE-Kafka-ClusterAdmin | Messaging / Kafka | Erin Kowalski | In review | 14 | 5 SNOW |
| PROD-PagerDuty-AccountOwner | ITSM / PagerDuty | Marcus Liu | Current | 4 | — |
| PROD-Okta-SuperAdmin | Identity / Okta | Sandra Volkov | In review | 9 | 2 SNOW |
| PROD-1Password-OrgAdmin | Secrets / 1Password | Priya Anand | Current | 6 | — |
| DEV-TerraformCloud-OrgAdmin | IaC / TF Cloud | Jamal Reeves | In review | 12 | 1 SNOW |
| PROD-Cloudflare-SuperAdmin | Edge / Cloudflare | Erin Kowalski | Overdue 33d | 7 | 9 SNOW |
| PROD-Cisco-Meraki-OrgAdmin | Network / Meraki | Marcus Liu | Current | 4 | — |
| PROD-Veeam-Backup-Admin | Backup / Veeam | Sandra Volkov | In review | 9 | — |
| PROD-VMware-vCenter-Admin | Infra / vCenter | Priya Anand | Overdue 26d | 18 | 8 SNOW |
| PROD-ServiceNow-AdminRole | ITSM / ServiceNow | Jamal Reeves | Current | 22 | — |
Anomaly detector — 6 patterns surfaced
Patterns matched across all 30 safes: self-review SoD, dormant credentials (>180d), break-glass usage spikes, unassigned ownership, MFA-bypass abuse, cross-safe lateral movement. Each anomaly carries a specific regulatory anchor.
Owner is also a privileged member
PROD-AWS-OrgRoot owner (Sandra Volkov) appears in the safe's member list with privileged entitlement. Self-review violates SOX ITGC segregation-of-duties — reviewer cannot also be reviewed. Reassign owner to peer in IAM team.
Vault credential unused for 187 days
PROD-Vault-Root contains a service-account credential (svc-vault-rotator) last used 187 days ago. Either rotate-and-rebind to current usage or revoke per CIS Control 5.6.
5× normal usage in last 7 days
PROD-Windows-DA break-glass credential checked out 12 times in last 7 days vs 7-day rolling avg of 2.4. Investigate root cause (incident? misconfigured runbook?) per NYDFS 500.7.
Safe owner = (unassigned)
PROD-AWS-OrgRoot and PROD-Workday-Tenant both have (unassigned) as owner. ISO 27001 A.9.2.3 requires named owner per privileged access path. Assign within 5 business days.
Bypass token used 3× in 24h
PROD-Okta-SuperAdmin MFA-bypass emergency token used 3 times yesterday by Sandra Volkov. Configured for break-glass only. Investigate normal MFA-flow failure or revoke bypass tier.
Lateral pattern across 3 prod safes
Actor jamal-reeves requested elevated entitlements across PROD-DB-Postgres, PROD-Vault-Root, and STAGE-DB-MySQL within 6-hour window. Pattern matches CIS 6.7 lateral-movement signature. Force re-justification of all 3.
ServiceNow access-review sync
Live sync to ServiceNow Access Review module via existing cyberark-connector-observability-exporter pipeline. Tickets created on certification-overdue event, closed on reviewer-decision event. Stale-ticket auto-escalation at 21 days.
| Ticket | Subject | State | Assignee | Age |
|---|---|---|---|---|
| SNOW-RITM4421882 | PROD-DB-Oracle quarterly cert | Awaiting review | Sandra Volkov | 8 days open |
| SNOW-RITM4422001 | PROD-Windows-DA emergency review | Approved | Erin Kowalski | Closed 2d ago |
| SNOW-RITM4422103 | PROD-AWS-OrgRoot annual cert | Escalated | (unassigned) | 21 days open |
| SNOW-RITM4422244 | PROD-Vault-Root rotation review | Awaiting review | Jamal Reeves | 11 days open |
| SNOW-RITM4422311 | PROD-Salesforce-Admin quarterly | In review | Erin Kowalski | 4 days open |
| SNOW-RITM4422401 | STAGE-DB-MySQL biannual | Awaiting evidence | Jamal Reeves | 16 days open |
| SNOW-RITM4422477 | PROD-Okta-SuperAdmin MFA-bypass review | In review | Sandra Volkov | 3 days open |
| SNOW-RITM4422511 | PROD-Cloudflare-SuperAdmin biannual | Reassigned | Erin Kowalski | 9 days open |
Audit chain
Every certification action — cert started, review decision recorded, anomaly flagged, member added/removed, SNOW ticket opened — is emitted as a hash-chained event. Each event signs the prior event's hash, making the log tamper-evident.
Why this surface exists
CyberArk PAM is the standard for privileged access vaulting in regulated industries (banking, healthcare, defense). The runtime ops problem is not storing the credential — it's continuously certifying that the right humans still need privileged access, before SOX/ISO audit windows close. This surface compresses the cycle time of quarterly cert from 4-6 weeks down to 4-6 days by visualizing the 5 anomaly patterns auditors look for.
Buyer: CyberArk admins · Compliance teams running quarterly PAM access reviews · Audit committees · ISO 27001 / SOC 2 / NYDFS auditors during evidence-collection windows.
Regulatory anchors: SOX ITGC · PCI DSS 4.0 (Req 7 + 8) · NIST 800-53 AC-2/AC-5/AC-6 · CIS Controls v8 Control 5/6 · ISO 27001 A.9 · NYDFS Part 500.7.
KG Suite tie-back: Every operator decision on this surface emits an audit-stream event (hash-chained, ed25519-signable). Vault-contract data classification follows the Decision Card v0.3 pattern (data_vault_targets + retention_envelope). Incident escalations match the AI Incident Card profile shape. Evidence bundles align with the AI Evidence Format spec.
Static-only doctrine: No backend. No login. No telemetry. All synthetic data is baked into this HTML page as JavaScript constants. Nothing leaves the tab. Frame as readiness / evidence / posture / controls / scaffolding — never "compliant" or "certified" without an externally-attested audit.