How CloudGrant compares to PAM and just-in-time access tools
A friend sent us a list of privileged access management tools and asked how we stack up. This is the honest version: which of them do what CloudGrant does, what each one costs where a price is printed, and where CloudGrant is the weaker choice.
The short answer #
Most of that list is a different product. Every tool in it is built around a credential vault, session recording, or elevating a local admin on a laptop. CloudGrant has none of those. It does one thing: an engineer asks for access to an AWS account, role or permission set with a reason, someone approves it, the access exists for the window they asked for, and CloudGrant takes it away again. Everything that happened is written down with the person's name on it.
The products we actually compete with are the cloud access brokers: Apono (now part of 1Password), P0 Security, BeyondTrust Entitle, Okta Access Requests, CyberArk Secure Cloud Access, and the free AWS sample called TEAM. AWS itself still does not ship the request-approve-expire loop. Its own documentation points customers at four partner products or at the sample.
Three things separate CloudGrant from those brokers. The price is fixed per tier and published on this site, not quoted after a call: $5,988 a year for the package most teams want, with no per-seat line. It runs in one AWS region in Frankfurt and is built by a Swiss company. And it exists to take standing access to zero and keep you audit-ready, not to sell an identity-governance program - a governance broker like ConductorOne prices its programs starting at a thousand identities.
This page was checked against each vendor's own site, AWS Marketplace listing or documentation on 8 September 2026. Every claim has a source at the bottom. If something is wrong, tell us at hello@buri.cloud and we will fix it.
Who this is for #
You are on AWS, security and compliance are not optional for you, and you want standing admin gone - zero standing privilege, with a full audit trail to show for it, not just a slower approval form. You want the request-approve-expire loop itself, not a credential vault or a session recorder bundled around it. That is who we built CloudGrant for. See the packages or try it on a sample company before connecting anything.
If that is not you, the list below says where to go instead.
Three kinds of tool get called "PAM" #
Vault and session proxy. The product owns the credential. It stores passwords and keys, rotates them, checks them out to a person for a task, and often sits in the connection so it can record the session. CyberArk Privileged Access Manager, Delinea Secret Server, BeyondTrust, Keeper, One Identity, ARCON and Symantec are this. It fits servers, databases, network gear and Windows admin accounts, where a long-lived secret exists and someone has to guard it.
Cloud access broker. There is no secret to guard, because nobody holds admin. The broker turns a cloud permission on for a fixed window after approval and off again when the window closes. AWS already issues short-lived credentials and already has the assignment model (permission sets, roles), so the broker only has to run the loop around them. Apono, P0, Entitle, Okta Access Requests, CyberArk Secure Cloud Access, Britive, ConductorOne and Opal are this. So is CloudGrant.
Enterprise suite. The big vendors now sell both, bundled with identity governance, endpoint elevation and remote access, and quote a price per program. Saviynt, CyberArk and Delinea's platforms are this. Rollouts are measured in months.
CloudGrant is the second kind, for AWS only, without the vault and without the session recorder. If you need those, the first kind is the right shelf to shop on.
The list you were sent #
What the Expert Insights article says about each vendor, and what we could verify. "Identity Center JIT" means the product can hand out an AWS IAM Identity Center permission set for a limited time after approval, which is the specific thing CloudGrant does.
| Vendor | What it is, per the article | Identity Center JIT | Published price | Buy it when |
|---|---|---|---|---|
| JumpCloud | Directory, device management and a privilege add-on | Not found in its docs | Directory packages $9 to $13 per user per month; the PAM add-on is quote-only | You want one vendor for laptops, SSO and directory, and privileged access is a side feature |
| ThreatLocker Elevation Control | Elevates an application on an endpoint without granting local admin | No | Quote | Your problem is local admin on Windows and Mac laptops |
| One Identity Safeguard | Vault plus session recording for large enterprises, on-prem or hybrid | Not on AWS's validated partner list | Quote | You need tamper-evident recordings of admin sessions on servers |
| Keeper KeeperPAM | Cloud PAM with zero-knowledge vault, session recording and rotation | Not found in its docs | Keeper's own page says KeeperPAM is sold "through Sales only"; the article's $85 figure is the article's | You already run Keeper for passwords and want the vault extended to servers |
| ARCON PAM | Banking-grade vault, on-prem, with analytics | Not on AWS's validated partner list | Quote | You are a regulated bank with on-prem estate and an auditor who names ARCON |
| BeyondTrust Privileged Remote Access | Brokered, recorded sessions for vendors and contractors | This product, no; BeyondTrust's Entitle, yes (see below) | Quote | Third parties need supervised access to your systems |
| Symantec PAM (Broadcom) | Vault and session recording as a virtual appliance | Not on AWS's validated partner list | Quote | You are already a Broadcom shop |
| CyberArk Privileged Access Manager | The enterprise vault benchmark, 500+ integrations | This product, no; CyberArk's Secure Cloud Access, yes (see below) | Quote | You are a large enterprise buying the full CyberArk platform |
| Delinea Secret Server | Vault with JIT provisioning and approval workflows | Its Identity Center integration is for visibility and finding over-privileged users, not time-bound assignment | Quote | You need a vault with fine-grained in-session controls |
| ManageEngine PAM360 | Vault plus certificate and SSH key management | Not on AWS's validated partner list | $7,995 a year for 10 admins and 25 keys, up to $49,995 for 200 admins | You want a self-run vault with a printed price and manage SSH keys and certificates too |
| Saviynt Cloud PAM | Converged PAM and identity governance | Yes, time-bound access to permission sets and groups | Quote | You are buying identity governance for the whole company and want PAM inside it |
Three of the eleven vendors will do what CloudGrant does for AWS Identity Center once you buy the wider platform: Saviynt, CyberArk through its separate Secure Cloud Access product, and BeyondTrust through Entitle. None of the three prints a price.
The tools we actually compete with #
| Product | Status, Sept 2026 | Identity Center JIT | Price model | Published price | Where it runs |
|---|---|---|---|---|---|
| CloudGrant | Onboarding first teams | Yes, plus IAM roles | Flat per workspace | $2,388 to $11,988 a year, on this site | AWS Frankfurt, one region; Swiss company |
| Apono | Acquired by 1Password, 15 June 2026 | Yes; on AWS's validated list | Quote | None; pricing page says "Book a demo" | New York and Tel Aviv; region not published |
| P0 Security | Independent | AWS, GCP, Azure; Identity Center not named in its listing | Per user, 100-user block | $5,000 per year for 100 users on AWS Marketplace; $50 per user per month above that | US company; region not published |
| BeyondTrust Entitle | Acquired by BeyondTrust, April 2024 | Yes, documented ("temporary permission set") | Per affected user, quote | None; Marketplace says "request a private offer" | US company (Georgia) |
| Okta Access Requests | Part of Okta Identity Governance | Yes; on AWS's validated list | Add-on per Okta user, quote | None published | Requires Okta Workforce Identity |
| CyberArk Secure Cloud Access | Separate SKU from the vault | Yes; on AWS's validated list; records console sessions | Quote, 30-day trial | None published | US company; docs list EU regions including Frankfurt |
| Tenable Cloud Security | Formerly Ermetic | Yes; on AWS's validated list | Part of a CNAPP, quote | None published | US company |
| ConductorOne (now C1) | Independent | Access requests across identity graph | Per identity; programs of 1,000 to 20,000 identities | $100,000 a year on AWS Marketplace | US company; "commercial, regional and federal hosting" |
| Britive | Independent | AWS IAM and STS; Identity Center not named in its listing | Package | Starter $70,000 a year, Core $100,000 on AWS Marketplace | US company |
| Opal Security | Independent | Cloud access requests; not verified this round | Quote | None; pricing page is a demo form | US company |
| Teleport | Independent | Access Requests to resources Teleport proxies | Monthly active users plus protected resources | Priced on request | Cloud or self-hosted; US company |
| StrongDM | Independent | Proxies AWS console and CLI | Per user, single SKU | "Talk with Sales" | US company |
| Hoop.dev | Independent, open source core | Gateway model | Per identity | Enterprise on request; MIT core free | Self-host or cloud |
| Sym | Independent, small | Terraform and Slack workflows | Quote | None published | US company (Boston) |
| Common Fate | Wound down 15 April 2025 | Was the closest AWS pure-play | - | - | - |
| Indent | Shut down July 2024 | - | - | - | - |
| AWS TEAM | Open-source sample, release 1.5.0 on 26 June 2026 | Yes | Free; you run it | $0 licence plus your engineers' time and the AWS bill | Your own AWS account |
Apono, now 1Password #
Apono was the broadest of the pure-plays: AWS, Azure, Google Cloud, Kubernetes, databases, and a long list of request channels. 1Password bought it on 15 June 2026 for a reported $250 to $300 million. That is good news for the category and worth knowing if you are a 1Password customer, because the JIT layer will land in the platform you already pay for. The trade-off is that Apono never printed a price and does not now, and a 1Password-sized buyer is a company, not a ten-person platform team. If you are on 1Password Enterprise, ask them. If you are not, the list price you would be quoted is anyone's guess.
P0 Security #
P0 is the one direct competitor that prints a number, and we respect that. Its AWS Marketplace listing is $5,000 a year for a block of 100 users, then $50 per user per month above that. For a team of 20, that block is cheaper than our Organization package and only slightly more than Team, and it covers GCP and Azure as well. Where CloudGrant differs: we price per workspace, not per user, so a team of 200 pays what a team of 20 pays; we run in one EU region under a Swiss company; and our approval and audit model is built around the compliance evidence an auditor asks for, not only around speed of access. P0 is a fair choice for a US team on more than one cloud.
BeyondTrust Entitle, Okta Access Requests, CyberArk Secure Cloud Access #
These three and Apono are the products AWS names on its own page as validated for temporary elevated access to Identity Center. All three do the thing. All three are quote-priced, and each comes attached to something bigger: BeyondTrust's PAM platform, an Okta Workforce subscription, or CyberArk's platform. If you already own the parent, the add-on is the path of least resistance and you should take it. If you would be buying the parent to get the add-on, the total is a different order of magnitude from anything on this page with a printed price.
ConductorOne, Britive, Opal #
These are governance platforms with JIT inside. ConductorOne's pricing page describes programs from 1,000 to 20,000 managed identities and its Marketplace listing is $100,000 a year. Britive lists Starter at $70,000 a year. Opal does not publish. They are strong products for a company with a security team, a procurement team and an identity graph to govern. They are not sized for a five-to-fifty-engineer team, and they do not pretend to be.
Teleport, StrongDM, Hoop.dev #
These sit in the connection path. They proxy SSH, Kubernetes, databases and, in Teleport's and StrongDM's case, the AWS console and CLI, and record what happened in the session. That is a real capability CloudGrant does not have. It comes with an agent or gateway to run, a per-user or per-resource bill, and a rollout that touches every server. If you need session recording of what an engineer typed, buy one of these. If you need to know who had which AWS permission set, for how long, approved by whom, CloudGrant answers that without anything in the data path.
The free option: AWS TEAM #
AWS publishes an open-source sample called TEAM (Temporary Elevated Access Management). It is free, it works, and a small AWS team still maintains it: release 1.5.0 shipped on 26 June 2026 and the repository was pushed to in the first week of September. If you have an engineer with time to own it, it is a legitimate choice, and we would rather you ran TEAM than ran standing admin.
What you take on with it, as of this month:
- It is sample code. The README says you are "responsible for testing, securing, and optimizing" it for production. AWS security bulletin AWS-2025-004 told customers to upgrade after a fix for requesters approving their own access.
- New installs need CloudTrail Lake, which AWS closed to new customers on 31 May 2026. Open issue #586 reports that deployment fails for accounts without an existing event data store; the workaround disables TEAM's session activity logs.
- Known open bugs. Issue #279, open since July 2024: two overlapping requests for the same access and the earlier expiry removes the later grant. Issue #433: the session lifetime limit not enforced. CloudGrant's revoke is reference-counted and tested against exactly that case, and expiry is enforced server-side with a sweep as backstop.
- It is Identity Center only. No IAM roles, no cross-account role model, no evidence export an auditor can verify.
- You run it. Amplify, AppSync, Step Functions, DynamoDB, and upgrades that have locked people out before.
First-year cost for a team of 20 engineers #
List prices only, annual terms, as published on 8 September 2026. Quote-only products are left out because any number we wrote would be a guess.
| Product | First year | Notes |
|---|---|---|
| CloudGrant Team | $2,388 | Flat, up to 3 AWS accounts, 90 days of history |
| CloudGrant Organization | $5,988 | Flat, unlimited accounts, on-call auto-approve, SIEM export, policy file |
| P0 Security | $5,000 | 100-user block on AWS Marketplace; multi-cloud |
| AWS TEAM | $0 licence | Plus the AWS bill and the engineer who owns it; needs an existing CloudTrail Lake store |
| ManageEngine PAM360 | $12,995 | 20 admins and 50 keys; a vault, not an Identity Center broker |
| JumpCloud Device Identity | $3,120 | 20 users at $13; directory and devices, with the PAM add-on quoted separately |
| Britive Starter | $70,000 | AWS Marketplace list |
| ConductorOne | $100,000 | AWS Marketplace list; programs start at 1,000 identities |
The honest reading of that table: for a US team on more than one cloud, P0 is the price competitor and a good product. For everyone else in the five-to-fifty range, the choice is between CloudGrant, running TEAM yourself, and a quote from a vendor whose programs start where your headcount ends.
Where CloudGrant is weaker #
We would rather you read this here than find it out in a security review.
- No credential vault. If you have shared passwords or long-lived keys to store and rotate, we do not do that. Use a vault.
- No session recording. We record who had which permission, when, why and on whose approval. We do not record the commands they ran. Your CloudTrail does, and every CloudGrant grant carries the requester's identity into your CloudTrail so those two records line up.
- AWS only. No Azure, no Google Cloud, no databases, no Kubernetes clusters. If you are on three clouds, Apono or P0 cover more.
- No SOC 2 or ISO 27001 report of our own yet. We can show you the controls; we cannot hand you a third party's attestation.
- The evidence pack is signed with our key. It shows that nothing changed after export. It does not independently prove that a human clicked approve; it is CloudGrant attesting that they did. There is no hash chain across events.
- A small company. CloudGrant is built and run by one person in Switzerland. Support is priority email. There are no phone lines and no contractual response times.
- New. We are onboarding our first teams. The vendors above have references you can call.
Who should buy something else #
- You need to vault and rotate secrets for servers, databases or network gear: CyberArk, Delinea, BeyondTrust, Keeper, ManageEngine, One Identity.
- You need recordings of what an engineer typed in a session: Teleport, StrongDM, or CyberArk Secure Cloud Access for the AWS console.
- You already pay for Okta Identity Governance, 1Password Enterprise, BeyondTrust or CyberArk: turn on their JIT and save the procurement cycle.
- You are on AWS, GCP and Azure and based in the US: P0 or Apono.
- You have an engineer who wants to own an AWS sample and an existing CloudTrail Lake store: TEAM.
- Your problem is local admin on laptops: ThreatLocker or JumpCloud.
Everyone else: see who this is for above.
Sources #
Checked 8 September 2026. Vendor pages change; if a link below no longer says what this page says, the page is wrong, not you.
- AWS, temporary elevated access for Identity Center and the four validated partners: docs.aws.amazon.com
- AWS TEAM: release 1.5.0, issue #586 CloudTrail Lake, issue #279 overlapping requests, issue #433 session lifetime, bulletin AWS-2025-004, CloudTrail Lake availability change
- Apono and 1Password: 1Password press release, SecurityWeek on the reported price, Apono pricing page
- P0 Security: AWS Marketplace listing
- BeyondTrust Entitle: Identity Center temporary permission set, AWS Marketplace listing, acquisition
- Okta Access Requests with Identity Center: AWS Partner Network blog
- CyberArk Secure Cloud Access: product page, 30-day trial
- ConductorOne: c1.ai pricing, AWS Marketplace listing
- Britive: AWS Marketplace listing
- Opal: opal.dev/pricing
- Teleport: pricing and its Enterprise pricing guide, revision 16 June 2026
- StrongDM: pricing
- Hoop.dev: pricing
- Common Fate: winding down
- Delinea and Identity Center: integration docs
- Saviynt and Identity Center: solution page
- ManageEngine PAM360: pricing
- JumpCloud: pricing
- Keeper: business and enterprise pricing
- The list this page answers: Expert Insights, top PAM solutions, updated 22 July 2026