Skip to content
Notifications
Clear all

Hot take: The mobile app is a gimmick; no one approves PAM requests from their phone.

1 Posts
1 Users
0 Reactions
3 Views
(@integration_maven_jane)
Estimable Member
Joined: 2 months ago
Posts: 100
Topic starter   [#16534]

Okay, I’m going to step into what might be a bit of a hornet’s nest here, but I’ve been thinking about this for a while. I work a lot with integrations and secure automation between systems, and the human-approval piece is always the trickiest part to get right.

The marketing for CyberArk’s Privilege Cloud and PAM solutions often highlights the mobile app for urgent, on-the-go approval of access requests. In theory, it’s a great idea—no more waiting for an admin to get back to their desk. But in practice, across the several environments I’ve seen or helped integrate (via their APIs for custom workflows), the mobile app approval is barely used. It feels more like a checkbox feature than a practical tool.

Here’s why I think it’s a gimmick in real-world scenarios:

* **Security vs. Convenience Mindset:** Approving privileged access is a high-stakes decision. The environment where someone is looking at their phone—in line for coffee, on public transit—is fundamentally at odds with the careful, audit-conscious mindset required. You’re more likely to rush or miss a detail.
* **The Workflow Reality:** Most PAM requests aren’t *that* urgent. If they are, there’s usually a phone call or a Slack/Teams alert to a person who then uses a *real computer* to review the full context (ticket details, change request links) and then approve. The mobile app can’t easily cross-reference these other systems in a usable way.
* **Integration Gap:** For true mobile utility, the app would need deep, seamless integration with ITSM platforms (ServiceNow, Jira), messaging apps, and email. While CyberArk has APIs, the mobile app experience feels siloed. You get a bare-bones request notification without the rich context needed for a confident approval. I’ve had to build Zapier-like workflows to bridge these contexts, and they always land in a web portal, not the mobile app.
* **Audit Concerns:** Every security team I’ve spoken to is uneasy about logging approvals from personal mobile devices. The “where and how” of the approval becomes a fuzzy variable in an otherwise strict audit trail.

I don’t doubt there are *some* edge cases where it’s been useful. But for the investment and complexity, it seems like a feature that looks great in a demo but sits unused. I’d argue the engineering effort would be better spent on richer web approvals, chatbot integrations, or more robust API hooks for automated, policy-based approvals.

Has this been anyone else’s experience? Or have you actually built a workflow where the mobile app is a critical, trusted part of your process? I’d love to be proven wrong with a specific use case.

~Jane


Stay connected


   
Quote