The PAM module of CRAF Solution. Directly addresses HKMA CRAF iC-2 (Access Control) requirements. Just-in-Time privileged access, email-based approvals, and compliance-ready audit trails — purpose-built for Hong Kong financial institutions.
Built from real-world experience managing privileged access in Hong Kong financial institutions. AccessGuard covers the full PAM lifecycle aligned to HKMA CRAF requirements.
No standing privileges. Users request access for a specific task with automatic expiry — reducing lateral movement risk.
Managers get standardized emails with APPROVE / REJECT / COMPLETED buttons. Click → Outlook opens pre-filled → Send. Done.
Full JumpServer API integration for account management, credential rotation, and bastion host session control.
Native AD integration. SamAccountName reconciliation, password resets, account locking, and OU-based grouping.
Auto-generated monthly PDF reports. Type-based summaries, trend analysis, anomaly flags, and compliance evidence.
Branch and role-aware escalation. Different branches route to different approvers automatically based on policy.
Log every access request, approval action, and session activity. Immutable audit trail for compliance audits.
Approvals work from any device. Managers can approve requests from their phone via email — no app required.
Automated password resets, rotation policies, and secure storage for service accounts and admin credentials.
See how the PAM module maps to CRAF iC-2 controls and strengthens your privileged access posture.