Priya found the doors. Now Omar has to decide the locks. Follow eight real privileged journeys at Abby Steel and see how protection follows risk, from Tier 0 to the furnace floor.
Module 3 ended with a list: 312 privileged accounts that no list had ever held. Priya found the doors; now Omar has to decide the locks. Following Ahmed, Chloe, Hannah, Tom, Marco and an AI agent through their real privileged journeys at Abby Steel, you see what happens today, what could go wrong, how PAM protects it and what changes for the person doing the work.
He pilots the design on ten production servers, then hands Sofia the problems any platform will have to solve, and what it must never let anyone bypass.
Module 3 ended with 312 privileged accounts that no list had ever held. Omar takes Priya's ranked list, draws the seven-box privileged access chain (person, identity, credential, path, privilege, target, action) and turns her four risk questions into four tiers.
Domain admins, backup operators and the certificate authority can take over everything. Omar empties the Tier 0 groups by default: access by ticket, a second approver, one hour, from a clean admin workstation, recorded and rotated. The PAM platform itself is Tier 0 from day one.
Ahmed's four-minute fix leaves no evidence and a password shared by forty servers. Credential management and session management are kept separate, credentials are injected through a proxy, the direct route is closed, SSH keys are cleared out, and endpoint privilege management ends local admin rights.
svc_furnace's dependencies are mapped before its password is changed, Chloe's pipelines get a secrets manager with short-lived credentials, cloud admin roles become eligible rather than active, and the AI operations agent gets its own identity, a human sponsor and task-scoped tokens.
Hannah's team swap a shared DBA account for named ones, Tom's 200 network devices each get their own vaulted password with change-controlled access on a separate management network, and the help desk reset path is treated as Tier 0.
Marco's shared, always-on VPN becomes named, approved, four-hour access to one workstation through a bastion host, designed around OT's safety constraints. Ukraine 2015 and Stuxnet show what happens when privileged access reaches industrial control.
MFA is matched to the tier and placed where no route can skip it. Session recording becomes a real control through notice, review, alerts on risky moments such as a PAM bypass, and encryption of the vault that holds every key.
Orphaned and over-privileged accounts are cleaned up, reviews and weekly discovery keep it clean, exceptions get owners and break-glass works even when PAM is down. Omar hands Sofia the problems and required capabilities, not a product.