Forrester's guidance to buyers in this market contains five words that describe an entire architectural shift: privilege is best when fleeting.

The traditional model was the vault. Administrative credentials were stored centrally, checked out when needed, checked back in afterwards, and rotated on a schedule. The credential existed permanently and access to it was controlled.

Fleeting privilege inverts that. The entitlement does not exist until someone needs it, is granted for a bounded window against a specific task, and is removed automatically afterwards. There is no standing credential to steal, because between requests there is nothing to steal.

That change matters because of what attackers actually do. Initial access is rarely the objective. Escalation is, and escalation requires that elevated privilege exists somewhere to be escalated to. Remove standing privilege and the attack path loses its destination.

What these systems control

Privileged identity management governs the accounts that can change things: domain administrators, root accounts, database administrators, cloud infrastructure roles, service accounts, and the emergency credentials nobody has used since the last incident.

The functional scope covers credential vaulting and rotation, session management and recording, just-in-time elevation, least privilege enforcement on endpoints and servers, secrets management for applications, discovery of privileged accounts nobody registered, and the audit trail across all of it.

Forrester's assessment of the current market is that these solutions are undergoing a transformation as vendors move beyond traditional privileged access controls toward more holistic identity security spanning human, machine, and AI agent identities.

Its recommended evaluation priorities are compact and useful: just-in-time privileged access, unification and integration to streamline operations, and features that enable audit compliance.

Three things, and the third is why the budget exists.

Two survivors from 2014

The Forrester Wave: Privileged Identity Management, Q1 2014 evaluated nine providers against eighteen criteria: BalaBit, BeyondTrust, CA Technologies, Centrify, CyberArk, Dell, Hitachi ID, Lieberman Software, and Thycotic. Forrester noted then that the market had matured significantly over the preceding three years.

The Q4 2023 edition used twenty four criteria.

The Forrester Wave: Privileged Identity Management Solutions, Q3 2025 evaluated ten vendors against twenty two criteria spanning current offerings and strategy, with customer feedback assessed alongside.

Of the nine names from 2014, two remain in the market under their own names. The rest were acquired, merged, or absorbed. Centrify and Thycotic combined to form Delinea. Lieberman went to BeyondTrust. CA went to Broadcom. Hitachi ID became Bravura. BalaBit went to One Identity.

That is heavy consolidation, and it produced a market where a small number of large specialists compete against identity platform vendors extending downward into privilege.

Note also that criteria fell from twenty four to twenty two while the stated scope expanded to cover machine and AI agent identities. Scope up, criteria down. That combination indicates capabilities that stopped discriminating, and vaulting is the obvious candidate. Every vendor does it competently now.

Inside the Q3 2025 evaluation

BeyondTrust placed as a Leader with the second highest score in the strategy category and maximum marks in thirteen criteria. Forrester described its vision as centring on identity-first security, helping organisations predict, discover, prevent, detect, and respond to identity risks in real time, with a roadmap featuring simplified privileged identity governance and AI-assisted intelligent access.

CyberArk placed as a Leader, cited for a bold vision extending privilege control across human, machine, and AI identities, backed by research investment and acquisitions including a certificate lifecycle management company and an identity governance company. Forrester credited it with strength in least privilege and just-in-time management, and singled out privileged task automation requiring no programming skills.

Delinea placed as a Leader, with Forrester describing a vision distinguished by becoming the source of truth for privileged identities through context-aware authorisation, intelligent access workflows, and identity threat detection. Its reference customers praised the interface, onboarding speed, and centralised policy management.

Segura was positioned for small and medium-sized organisations needing an affordable all-in-one solution across a wide range of privileged account use cases.

The pattern across those citations is worth noting. Three Leaders, and all three vision statements are about extending beyond privileged access into identity security generally. Nobody is differentiating on vaulting.

Why standing privilege is the problem

The just-in-time argument deserves unpacking because the alternative is so entrenched.

In most enterprises, privilege is granted and then persists. Someone needs administrative rights for a project, receives them, and keeps them after the project ends because removing access requires someone to notice and act. Multiply that across years of projects, role changes, and departures handled imperfectly, and the organisation accumulates a population of accounts with more entitlement than anyone intended.

Cloud and software-as-a-service adoption accelerated this considerably. Each platform has its own privilege model, its own administrative roles, and its own grant mechanism, and the aggregate is invisible from any single console.

The result is that an attacker who compromises an ordinary user account frequently finds it has more than ordinary rights, or finds a path to something that does within a few hops.

Just-in-time access breaks that by making the default state unprivileged. Elevation requires a request, carries a justification, is time-bounded, and expires without intervention. Nothing accumulates.

The obstacle is operational rather than technical. Engineers who currently work with standing access experience just-in-time as friction, and if the request process is slow or unreliable they will find ways around it, which reproduces the original problem with an audit trail that says otherwise.

Which is why unification and integration appear in Forrester's recommendations alongside just-in-time. An elevation request that resolves in seconds inside the tool someone is already using gets adopted. One that requires a separate portal and a manager's approval by email does not.

The agent problem lands here first

Of all the categories touching identity, this is where AI agents create the most acute difficulty, and the reason is simple: agents need privilege to do anything useful.

An agent that reads a dashboard needs little. An agent that provisions infrastructure, resolves an incident, modifies a configuration, or executes a remediation needs the kind of access this category exists to control.

Several properties make that harder than managing human privilege.

Agents are created programmatically, at a rate no joiner process was designed for, and frequently by other agents.

They operate continuously rather than during working hours, so behavioural baselines built around human patterns do not apply.

They act on behalf of people, which means the identity question has two layers: the agent's own identity, and the authority delegated to it. The correct model is delegated authority narrower than the delegator's, scoped to the task, with the chain reconstructable afterwards. Most infrastructure cannot express that today.

And they do not report anomalies. A human whose account behaves strangely eventually notices. An agent does not.

Forrester's framing of the market transformation names human, machine, and AI agent identities together, and CyberArk's cited vision extends privilege control across all three. That is the right direction and it is early. The practical question for a buyer with a serious agent programme is what the platform can express today about delegated, time-bounded, task-scoped authority, and what remains roadmap.

This also connects to the governance layer Forrester covers separately under agentic control planes, where the argument is that oversight must sit outside the runtime it supervises. Privilege management is one of the few controls that already works that way.

Why this actually gets funded

The third item in Forrester's list, features that enable audit compliance, is the least interesting technically and the reason most of these purchases happen.

Privileged access is where auditors look first, because it is where the highest-consequence actions occur. Regulatory regimes across financial services, healthcare, and critical infrastructure all require demonstrable control over administrative access, with evidence that access was appropriate, approved, monitored, and reviewed.

A PIM platform produces that evidence as a by-product of operating. Session recordings, approval records, elevation logs, and access reviews are exactly what an examiner asks for.

That produces a useful dynamic for security teams, who can fund a control they want on a compliance justification that finance understands. It also produces a risk, which is that a deployment scoped to satisfy an auditor covers the accounts the auditor asks about rather than the accounts an attacker would use.

The gap between those two sets is where incidents originate. Service accounts, application credentials, cloud roles, and the administrative access embedded in automation are frequently outside the compliance scope and squarely inside the attack path.

Discovery capability matters for exactly this reason, and it is worth weighting more heavily than the compliance reporting that justifies the purchase. You cannot manage privileged accounts you have not found, and the ones nobody registered are disproportionately the ones nobody is watching.

Analyst Source

Forrester Research

Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of privileged identity management, scored in Q1 2014 against 18 criteria covering nine providers, in Q4 2023 against 24 criteria, and in Q3 2025 against 22 criteria covering 10 vendors across current offerings, strategy, and customer feedback. Forrester covers workforce identity, customer identity, and identity governance as separate markets.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.