Hello everyone,
I've been tasked with leading the evaluation for a Privileged Access Management (PAM) solution at my organization, and CyberArk is, of course, a dominant name on our shortlist. We are a heavy ServiceNow shop, and a native, bi-directional integration with the ITSM platform is a non-negotiable requirement for workflow automation and compliance reporting.
While I'm aware CyberArk has integration capabilities, my initial research suggests its integration with ServiceNow often requires custom scripting, use of the MID Server, or reliance on third-party integration platforms. This introduces complexity I'd prefer to avoid.
Before we dive too deep into vendor demos and proof-of-concepts, I wanted to tap into the community's practical experience. I'm particularly interested in alternatives that offer a more "out-of-the-box" native integration with ServiceNow, ideally via the ServiceNow Store or a well-documented, supported application.
My core evaluation criteria, beyond the ServiceNow integration, include:
* **Total Cost of Ownership:** This goes beyond licensing. I'm keen to understand the implementation effort, ongoing maintenance, and any hidden costs related to the integration itself.
* **User Reviews on Integration Workflow:** How seamless is the day-to-day operation? For instance:
* Can access requests and approvals flow entirely within a ServiceNow ticket?
* Does session access or password checkout initiate from the ServiceNow interface?
* Are privileged account reconciliations and audit reports automatically synced to ServiceNow CMDB?
* **Implementation Timeline:** Specifically, how long does the ServiceNow integration component typically take to configure and deploy after the core PAM product is in place?
* **Exit Strategy Considerations:** This is often overlooked. If a solution uses proprietary connectors or deeply customizes the ServiceNow instance, what are the implications for switching vendors or upgrading ServiceNow?
I would be grateful for any insights on products like BeyondTrust Password Safe, Delinea (formerly Thycotic), HashiCorp Vault, or others you've evaluated or implemented. Concrete examples of how the integration works in practice, or pitfalls you encountered during procurement and integration, would be incredibly valuable to my process.