1. Vendor and Product Reality

CyberArk Software, founded in 1999 and publicly traded on NASDAQ, is the established leader of the privileged access management market. Its core architecture is the Digital Vault, a hardened, FIPS-validated credential store, fronted by the Privileged Session Manager (PSM) for session brokering and recording, the Central Policy Manager (CPM) for automated credential rotation, and the Password Vault Web Access (PVWA) and CyberArk Identity for user-facing workflows. Adjacent products extend the model: Endpoint Privilege Manager removes local administrator rights on workstations and servers, Conjur Secrets Manager (acquired by CyberArk and later released as open source) brokers application and DevOps secrets, and the Identity Security Platform integrates SSO, MFA, and lifecycle for the broader workforce.

The customer base is concentrated in regulated and high-value verticals, global banks, payment networks, defense primes, federal agencies, energy utilities, where SOX ITGC, PCI DSS, NIST 800-53, and similar regimes mandate vaulting, rotation, session recording, and just-in-time elevation. CyberArk's dominant strengths are its credential vault hardening, the PSM jump-host model that interposes a recorded session between the privileged user and the target system, and an extensive plug-in catalog covering operating systems, databases, network gear, cloud APIs, and SaaS administrative consoles.

The platform has evolved from on-premises infrastructure toward Privilege Cloud SaaS, with the Identity Security Platform positioning CyberArk as a workforce-and-machine-identity vendor rather than purely a PAM vendor. Within its scope, CyberArk is the architectural reference for privileged credential brokering: a privileged session does not bypass the vault, a credential does not leave the vault unrotated, and a session is recorded for forensic replay.

2. The Architectural Gap

CyberArk's architecture is a brokering and recording architecture, not a governance-chain architecture. The PSM session is interposed and recorded; the vault enforces check-out and rotation; the CPM rotates on schedule. But the events the platform produces, a vault check-out, a session recording start, a policy evaluation, a credential rotation, are administrative artifacts written to CyberArk's own database. They are not credentialed observations admitted through a five-property chain with recursive re-entry, and CyberArk's own service identity is not a property-one authority within a published taxonomy.

This shows up in a well-understood architectural property of centralized brokering: the broker is the trust anchor, so the security of the whole model rests on the security of that anchor. CyberArk has hardened the vault extensively, and this is exactly what its customers pay for. The point here is not a weakness in CyberArk's execution but a difference in architectural shape: a single brokerage point recording into a single audit log does not, by construction, produce composite admissibility, evidential weighting against authority-credentialed observations from outside the broker, or graduated actuation outcomes. A privileged session is permitted, denied, or terminated; it is not weighted against authority class, credential continuity, corroborating observations, and operational context to produce a graduated outcome from a defined mode set.

This is a difference in architectural shape rather than a defect to be patched: adding signed audit fields, hash-chained logs, or federated vaulting on top of a brokering model does not by itself produce the recursive closure that defines the chain, the property by which every actuation produces actuation-state observations that re-enter the chain at property one. The platform's commercial strength, being the trusted broker, is the same property that keeps it outside chain topology by default; chain participation requires that the broker itself be a credentialed actuator within a chain it does not own. This is a positioning axis, not a criticism of CyberArk's execution, which within its scope is the reference implementation for privileged brokering.

3. What the AQ Governance-Chain Primitive Provides

The Adaptive Query governance-chain primitive specifies five structural properties with recursive closure for every mutation in a conforming system. Authority-credentialed observation means every input that can affect state, a privileged session request, a vault check-out, a credential rotation, an emergency break-glass, arrives as an observation signed by an authority within a published taxonomy; uncredentialed inputs are rejected or downgraded to a lower-authority class for which a credential is structurally implied.

Evidential weighting composes authority class, credential continuity, corroborating observations from independent authorities, governance policy, and operational context into a structured contribution. Composite admissibility evaluates weighted observations against the proposed privileged action and produces a graduated outcome from a defined mode set, full session permitted, session permitted under elevated recording, time-boxed conditional permit, observation-only permit, deferred for second-authority approval, refused with documented evidence, rather than a binary permit/deny.

Governed actuator execution produces the resulting privileged-session commitment with reversibility evaluation (can the actions be rolled back), harm minimization under credentialed configuration (least-privilege scoping derived from the chain's evidence), and post-actuation verification. Lineage-recorded provenance records every observation, weighting, decision, actuation step, and verification with credentials, structurally tamper-evident, supporting forensic reconstruction of any privileged action under any past time. Recursive closure means every privileged actuation produces observations that re-enter the chain, a session command observed at the target becomes a property-one observation for downstream chains. The primitive is technology-neutral and composes hierarchically (workstation, vault, jurisdiction, coalition) so privileged operations spanning multiple vendors and clouds are governed under one chain. The inventive step disclosed in U.S. Provisional Application No. 64/049,409 is the closed five-property chain as a structural condition for privileged actuation across heterogeneous trust domains.

A skilled implementer can build this over an existing PAM deployment: define the authority taxonomy and issue credentials to each participating authority; place an admissibility gate in front of the actuation surface (the PSM session-start path, the CPM rotation trigger, the break-glass path); implement the evidential-weighting and composite-admissibility evaluation as a service that consumes credentialed observations and emits a graduated mode selection; drive the existing actuator (the PSM connector, the vault check-out) from the selected mode; and append each observation, weighting, decision, actuation step, and verification result to a tamper-evident lineage record. Embodiments and variations include: authority taxonomies scoped per workstation, per vault, per jurisdiction, or per coalition; graduated mode sets ranging from binary permit/deny up to the full set (full permit, permit under elevated recording, time-boxed conditional permit, observation-only permit, deferred for second-authority approval, refused with documented evidence); lineage stores realized as append-only logs, signed hash chains, or permissioned ledgers; and deployment either as an external gate in front of an unmodified PAM product or as an embedded substrate within one. The chain is technology-neutral as to credential scheme, transport, and storage.

4. Composition Pathway

CyberArk integrates with AQ as a privileged-actuation surface running over the governance-chain substrate. What stays at CyberArk: the Digital Vault hardening, the PSM session brokering and recording, the CPM rotation schedules, the connector and plug-in catalog, Endpoint Privilege Manager, Conjur for secrets, and the customer-facing PVWA and Identity Security Platform UX. CyberArk's intellectual property in vault hardening and session recording, the part regulators and auditors actually pay for, remains its differentiated layer.

What moves to AQ: the privileged-session admissibility decision, the policy evaluation, and the audit lineage. Integration points are concrete. PSM emits a session-start intent to an AQ admissibility gate rather than evaluating its own policy; the gate runs property-three evaluation against authority-credentialed observations from the requesting user, the target system's owner, the change-management authority, the threat-intelligence authority, and the operational-context authority, and emits a graduated actuation back to PSM. The session itself is recorded both by PSM (for replay) and by AQ as lineage observations (for chain audit). CPM rotation events become credentialed observations; emergency break-glass becomes a graduated outcome with mandatory second-authority weighting.

The new commercial surface is privileged-actuation governance that survives platform migrations and spans across cloud providers, sovereign jurisdictions, and coalition operations, the use cases where CyberArk's customers are increasingly stuck. The chain belongs to the customer's authority taxonomy, not CyberArk's database, which makes audit lineage portable and supports the cross-jurisdiction privileged operations that defense and multinational financial customers actually have.

5. Commercial and Licensing Implication

The fitting arrangement is an embedded substrate license: CyberArk embeds the AQ governance-chain primitive into Privilege Cloud and the Identity Security Platform and sub-licenses chain participation to its customers as a tier of the privileged-actuation subscription. Pricing aligns naturally to credentialed-mutation volume rather than per-vault-or-target seat, matching how regulated customers actually consume privileged actuation.

What CyberArk gains: a structural answer to the "broker is the single point of trust" problem that has driven competitive pressure from BeyondTrust, Delinea, and cloud-native PAM offerings, a defensible architectural floor against the converging post-quantum and zero-trust pressures, and a credible position for sovereign and coalition deployments where customers cannot accept a single vendor as the sole trust anchor. What the customer gains: portable, vendor-independent audit-grade lineage of privileged actuation, graduated outcomes that match operational reality better than binary permit/deny, and a chain that survives the migration from CyberArk on-premises to Privilege Cloud or to a successor vendor, which makes the platform stickier because its hardening and connector value are what give it preferred access to that substrate.

6. Disclosure Scope

The inventive subject matter described in this article, the five-property governance chain (authority-credentialed observation, evidential weighting, composite admissibility evaluation, governed actuator execution, and lineage-recorded provenance, composed with recursive closure), is disclosed in U.S. Provisional Application No. 64/049,409. Statements in this article about CyberArk and its products (Privileged Access Manager, PSM, CPM, PVWA, CyberArk Identity, Endpoint Privilege Manager, Conjur, the Identity Security Platform, and Privilege Cloud), about the privileged access management market, and about other vendors are provided as external context to situate the disclosed invention. Those statements describe third-party systems as generally understood at the date of publication and are not claims of U.S. Provisional Application No. 64/049,409. CyberArk and the named products are trademarks of their respective owners; no affiliation or endorsement is implied. The scope of what is claimed is defined solely by the application as filed.