Monopam · Vendor Privileged Access

Vendors get a window.
Not a network.

Third-party engineers, integrators, and support teams get exactly one thing: a time-boxed, recorded, approval-gated session to the systems they maintain. No VPN account, no shared login, no standing credentials waiting to be phished.

  • Approval-gated invitations
  • Hard expiry, enforced twice
  • Every session recorded
What you get

The full vendor lifecycle, governed.

Most vendor breaches start with an account nobody remembers creating. Monopam replaces the VPN-account workflow with a lifecycle: invite, approve, connect, expire, review. It runs self-hosted and air-gapped, so OT sites and regulated networks get the same control without a SaaS dependency.

Invitations, not accounts

A vendor user starts as an invitation request that passes an approval flow before any identity exists. Once approved, enrollment is a passwordless magic link: no password to share, intercept, or reuse.

  • Approval flow before the invitation is sent
  • Passwordless magic-link enrollment
  • Per-vendor authorized email domains
  • MFA enforcement per invitation

Time-boxed by design

Every external account carries an expiry. It is enforced in the PAM layer and mirrored into the identity layer, so a bypass attempt hits a second wall. Inactivity disables accounts that stop being used.

  • Hard expiry on every external account
  • Expiry mirrored to the identity platform
  • Automatic disable after inactivity
  • Contract window per vendor organization

Sessions watched end to end

Vendor connections can require just-in-time approval before they start, are forced through session recording, and notify the sponsor the moment the vendor connects.

  • Just-in-time connection approval per vendor
  • Forced session recording for external users
  • Sponsor notified on every connection
  • IP and network restrictions per vendor

Governance built in

Vendor organizations are first-class objects: delegated vendor admins manage their own team through a portal, access reviews attest who still needs access, and every action lands in the audit trail.

  • Vendor portal with delegated team management
  • Periodic access reviews with disable-on-reject
  • Per-vendor audit trail and reporting
  • Invitations from the portal still pass your approval
How it works

Invite. Connect. Expire.

01

Invite the vendor

Request an invitation with a vendor organization, an expiry, and an MFA requirement. Your approvers confirm it; the vendor enrolls through a magic link.

02

Broker the session

The vendor connects through the Monopam gateway: approval-gated if you require it, recorded always, with the sponsor notified in real time.

03

Expire and review

Access ends when the window ends, at both the PAM and identity layers. Access reviews confirm who still needs access; a rejection disables the account.

Ready to start managing
identities the right way?

Spin up a fully-loaded trial tenant in under five minutes. No credit card. No sales gate.