Skip to main content
Question

Department-Level Segregation - Password Safe Use Case Validation

  • December 14, 2025
  • 2 replies
  • 44 views

Forum|alt.badge.img+3

Can BeyondTrust Password Safe support strict logical segregation between two departments (Network Division and IT Security Division) within the same Password Safe deployment, ensuring no visibility of assets, accounts, users, or sessions across divisions?

 

Component Network Division IT Security Division
PAM Admin Network PAM Admin Security PAM Admin
Assets Network devices Security infrastructure
Accounts Network privileged accounts Security privileged accounts
Users Network engineers Security engineers
Policies Network-specific Security-specific
Reports Network only Security only
Configuration Network Only Security Only

2 replies

Pulitros144
Forum|alt.badge.img+4
  • Veteran
  • December 15, 2025

@AmilaK Yes, you just need to configure the Smart Rules and Groups to see only what they need and have acess to only the specified features


Forum|alt.badge.img
  • January 16, 2026

Other option (more drastic option) is to create multiple organizations with in the main configuration page.  This makes everything separate, including UVM appliances, but the backend database can be shared.