Tanflow PAM · Capability
External Access Monitor
A PAM gateway only protects the door people use. The External Access Monitor watches for anyone who climbs in a window.
Overview
Close the bypass blind spot
Any privileged access platform has one weakness: a login that skips the gateway entirely - a local console, a forgotten direct route, a shared password used off-platform. Tanflow's External Access Monitor deploys a lightweight agent on chosen targets to detect and report those out-of-band logins.
Track server logins that happen outside PAM, so gateway bypass no longer goes unseen.
Enable monitoring per connection to deploy a small agent on the target server - opt in only where you need it.
See monitored targets, active agents and stale agents at a glance to keep coverage honest.
Each monitored target reports events and last check-in, building a record of external activity.
Export the monitoring picture for review, reporting and evidence.
Why it matters
Outcomes you can put in front of an auditor
- Eliminates the "someone logged in around PAM" blind spot
- Surfaces forgotten direct routes and shared off-platform credentials
- Proves the gateway is actually the only path - or shows where it is not
- Targeted rollout: monitor only the servers that matter
- Supports incident investigation with out-of-band evidence
Part of Tanflow PAM
This capability is built into Tanflow PAM - the zero-agent privileged access platform that deploys in 2-4 weeks on your infrastructure.
Explore the full platform →FAQ
Common questions
Does every server need the agent?
No. Monitoring is enabled per connection, so you deploy the lightweight agent only on the targets where out-of-band access matters.
What does the monitor actually report?
It reports server logins that occur outside the PAM gateway, along with agent status and last check-in, so bypass activity becomes visible and exportable.
See External Access Monitor in action
A focused demo against your environment and your compliance requirements.