On Aug. 27, 2026, the mesh-VPN vendor opened a waitlisted public beta of Tailscale PAM, a privileged access management layer built into its existing admin console rather than sold as a separate tool.
The product is built on Border0, a PAM company Tailscale acquired earlier this year. Tailscale PAM product manager XingLu Wang said in a launch video the goal is to eliminate standing privilege and shared credentials, swapping them for “granular access, and time-bound, specific access for specific users” who “never have to think about the credentials.”
Standard Tailscale policy restricts which machines a user can reach. PAM adds in-app controls on top, for example, limiting a database user to view and write commands while blocking deletes. The beta covers SSH, databases, Kubernetes, and Windows Remote Desktop through regional connectors, so there is no agent to install on every resource. It also ships browser-based access and session logs with video and text playback for audit.
For security leaders consolidating identity, ZTNA, and PAM spend, a ZTNA vendor natively entering the PAM market puts integration and pricing pressure on CyberArk, BeyondTrust, and Delinea. The connector model and built-in session recording map directly to federal least-privilege and continuous-audit mandates.
Source: Tailscale



Leave a Reply