Tanflow IAM Suite & PAM - enterprise identity and privileged access security for the modern enterprise. Get a Demo →

Tanflow PAM · Capability

Roles & Access Control

Administer the platform under least privilege: cumulative tiers from User up to Super Admin, with the most sensitive powers reserved and audited.

Overview

Least privilege applies to administrators too

Whoever administers a PAM platform holds enormous power, so that power is itself governed. Tanflow models administration as cumulative role tiers and delegated roles, defines what each can do across resources, and reserves the most sensitive action - revealing a vaulted credential - for the top tier alone.

Administrative tiers

Cumulative levels of platform management from User up to Admin and Super Admin, each granting the tier below plus more.

Reserved vault reveal

Only Super Admin can reveal a stored vault credential, after MFA step-up, and every reveal is audited.

Delegated roles

Purpose-built roles - Connection Manager, Identity Manager, Policy Manager - delegate a slice of administration without full rights.

Users & user groups

Manage individual users and organise them into groups for scalable assignment.

Granular, per-resource permissions

Roles define exactly what a member can do across connections, identities, policies and audit.

Why it matters

Outcomes you can put in front of an auditor

  • No single over-powered administrator by default
  • The most sensitive action - vault reveal - is reserved and logged
  • Administration delegated safely to the right specialists
  • Assignment scales through groups, not one user at a time
  • Clear separation of duties for auditors to verify

Part of Tanflow PAM

This capability is built into Tanflow PAM - the zero-agent privileged access platform that deploys in 2-4 weeks on your infrastructure.

Explore the full platform →

FAQ

Common questions

Can we delegate administration without granting full admin?

Yes. Delegated roles such as Connection Manager, Identity Manager and Policy Manager each own a defined slice of the platform without full administrative rights.

Who can reveal a stored credential from the vault?

Only the Super Admin tier, and only after MFA step-up verification - every reveal action is recorded in the audit trail.

See Roles & Access Control in action

A focused demo against your environment and your compliance requirements.