Every privileged access programme rests on one assumption so foundational it is rarely stated: that privileged sessions actually go through the PAM platform. Vault the credentials, record the sessions, police the commands - all of it protects only the access that traverses the gateway. The administrator who SSHes directly to the server using a key that predates the rollout is invisible to every one of those controls. Not blocked. Not recorded. Not seen at all.
The enterprise challenge: the path around the control
Bypass paths accumulate naturally in any estate. Old SSH keys authorised on servers years ago. Local administrator accounts created during builds. Direct database logins used by scripts and never inventoried. Emergency access arrangements that outlived their emergencies. None of these were created to defeat PAM - they simply predate it or escaped it - but each is a door that opens without the gateway knowing, and an attacker who finds one inherits privileged access with no vault, no recording and no command policy in the way.
The uncomfortable audit question follows directly: when the organisation presents its session recordings as evidence of privileged access control, what evidences that those recordings are complete? Coverage claims need a detector, not an assumption.
Why network restriction alone is not sufficient
The standard mitigation is network-level: firewall the targets so administrative ports accept connections only from the gateway. This is the right control and should be done - but it is a configuration, and configurations drift. Rules get broadened during incidents and never re-narrowed; new servers launch from templates that missed the restriction; cloud security groups are edited by teams outside the PAM programme. A preventive control with silent failure modes needs a detective control watching its back.
The Tanflow approach: watch the targets, not just the gateway
Tanflow PAM includes an External Access Monitor whose purpose is exactly this: detect server logins that bypass the PAM gateway. Rather than assuming the routing controls held, the platform observes login activity on the targets themselves and surfaces the sessions that did not originate from the gateway - the direct SSH login, the console access, the connection that arrived by a path the programme did not sanction.
This closes the loop on the zero-agent architecture. The gateway model's great strength is that coverage is architectural - route the access through the gateway and everything is vaulted, recorded and policed. The External Access Monitor verifies the one premise that strength depends on, converting "we believe all privileged access is controlled" into "and here is the detector that would tell us if it were not". Tanflow's own product comparison notes that this bypass-detection capability is generally absent from both open-source assemblies and legacy PAM suites.
Operating model
- Privileged access runs through the gateway as designed - authenticated, authorised, injected, enforced, recorded.
- The External Access Monitor watches for logins on protected targets that did not come through the gateway.
- Detected bypass logins are surfaced for triage: a forgotten SSH key to revoke, a misconfigured security group to fix, or - the case that justifies the whole capability - activity that warrants incident response.
- Findings feed remediation, and the bypass surface shrinks toward zero over time, with evidence of the shrinking.
Enterprise scenario
Consider an e-commerce operation six months into its PAM rollout, confident that production access now flows through the gateway. The monitor's first weeks tell the real story: a deployment host still reachable by three engineers' personal SSH keys, a database accepting direct logins from a reporting server nobody documented, and a nightly connection from a script using a credential that was supposed to have been vaulted. None of it malicious; all of it invisible until watched; each item now a ticket with an owner. The rollout's true completion date is the week the monitor goes quiet.
Security and audit implications
For security teams, bypass detection converts unknown-unknowns into a worklist and gives compromise of out-of-band credentials a tripwire it previously lacked. For auditors, it transforms the completeness claim behind every other piece of PAM evidence from assertion into monitored fact - a distinction assessors under frameworks like ISO 27001 and the RBI Cyber Security Framework are well equipped to appreciate.
Conclusion
A privileged access programme is only as strong as its guarantee that access actually passes through it. Tanflow PAM's External Access Monitor supplies that guarantee's missing half - the detector that watches for the path around the gateway - and in doing so turns PAM coverage from a hopeful assumption into a verified, auditable state.