PAM
Session Groups
Session groups bundle related session targets (SSH, RDP, database) so policies, approvers, and command restrictions are defined once and applied to every member. Add a new target to the group and it immediately inherits the group's policy. Group-level approvers can delegate individual request handling while a tenant administrator owns the group definition.
Groups make bulk onboarding practical -- a Kubernetes cluster with 40 nodes, or a database fleet with dozens of replicas, can be managed as a single access surface.
Key Configuration
- Group-level command policy preset
- Group approver chain
- Default session recording behavior
- Target auto-assignment rules (by tag, CIDR)