Isometric illustration of a violet shield on a circuit board, ringed by glowing platforms that are linked overhead by thin lines, on a dark navy background

Tailscale Enters PAM With an Agentless, Time-Bound Access Beta

On Aug. 27, 2026, the mesh-VPN vendor opened a waitlisted public beta of Tailscale PAM, a privileged access management layer built into its existing admin console rather than sold as a separate tool.

The product is built on Border0, a PAM company Tailscale acquired earlier this year. Tailscale PAM product manager XingLu Wang said in a launch video the goal is to eliminate standing privilege and shared credentials, swapping them for “granular access, and time-bound, specific access for specific users” who “never have to think about the credentials.”

Standard Tailscale policy restricts which machines a user can reach. PAM adds in-app controls on top, for example, limiting a database user to view and write commands while blocking deletes. The beta covers SSH, databases, Kubernetes, and Windows Remote Desktop through regional connectors, so there is no agent to install on every resource. It also ships browser-based access and session logs with video and text playback for audit.

For security leaders consolidating identity, ZTNA, and PAM spend, a ZTNA vendor natively entering the PAM market puts integration and pricing pressure on CyberArk, BeyondTrust, and Delinea. The connector model and built-in session recording map directly to federal least-privilege and continuous-audit mandates.

Source: Tailscale


Leave a Reply

Discover more from Digerati One (Di1) | AI Integration & Multi-Cloud Architecture

Subscribe now to keep reading and get access to the full archive.

Continue reading