Skip to content
English

Five ways to manage access, compared

When you pick a managed path to a set of hosts, databases, and accounts, there is usually more than one way to do it. This page puts five of them on the same ten aspects, so you can judge which one your environment needs.

What is compared is the approach, not the brand. The four columns on the left describe the common shape of each kind of approach and point at no particular product; the implementation you hold may already have extra components added, so read each cell against the criteria column to its right. The Custodexa column describes how this product behaves, and the capability domain behind it is named in the same cell.

  • The summary column says what the approach looks like in an ordinary deployment. The four columns on the left use “usually”, “mostly”, and “depends on the implementation” to show that these are descriptions of a shape rather than product specifications verified one by one.
  • The criteria column says what each cell was judged against, for example “the default configuration of the remote login service built into the operating system”. Where a situation is excluded by the criteria (an added component, a paid edition, a control system above it), the description does not apply.
  • In the Custodexa column the criteria position names the capability domain that behavior belongs to, and the product’s own documentation and specifications govern its meaning.
  • The verification date is when this comparison was last checked, shown above the tables.

Verified on2026-09-04

Access boundary

ApproachCommon shapeReading criteria
SSH jump hostUsually admits the whole login hostJudged against the default configuration of the remote login service that comes with the operating system; installations with an added authorization component fall outside this.
VPNMostly admits a whole network segmentJudged against the general shape of a network layer tunnel; deployments with an access control system above the tunnel fall outside this.
Open source bastionMostly grants per single targetJudged against what a community edition offers by default; paid editions and self-modified forks fall outside this.
Commercial PAMMostly grants per single target or accountJudged against the shape common to commercial privileged access management products; differences between editions and modules are not separated out.
CustodexaEvery asset can be set to direct connection, reason required, or approval requiredSpec:access-policy

Client installation

ApproachCommon shapeReading criteria
SSH jump hostUsers bring and configure their own connection clientJudged against the general practice of users connecting themselves; installations with an added web entrance fall outside this.
VPNTunnel software is installed on the user's deviceJudged against the shape that builds a tunnel on the user's device; browser-hosted access services fall outside this.
Open source bastionMostly connects through a browserJudged against the web interface a community edition offers by default; additional desktop clients are not counted.
Commercial PAMDepends on the implementation; some need a dedicated clientJudged against the deployment prerequisites in a product's public documentation; where one product offers several access modes, the common one is taken.
CustodexaA browser is enough to connect, and users install nothingSpec:session-workspace

Approval before connecting

ApproachCommon shapeReading criteria
SSH jump hostUsually no approval step before a connectionJudged against the general practice where an account and a key are the authorization; installations wired to a ticketing system fall outside this.
VPNUsually authorized once, when the tunnel is builtJudged against the tunnel's own authentication; deployments where an upper system carries per-connection approval fall outside this.
Open source bastionDepends on the implementation; mostly no per-connection approvalJudged against the flow a community edition offers by default; ticketing integration plugins are not counted.
Commercial PAMMostly carries a request and approval flowJudged against the request flow described in a product's public documentation; whether it is turned on depends on how it was rolled out.
CustodexaA multi-asset task approves account scope and time window per item, creating time-limited authorization at approvalSpec:access-request

Session recording

ApproachCommon shapeReading criteria
SSH jump hostUsually leaves system login recordsJudged against the login and audit logs built into the operating system; installations with an added capture tool fall outside this.
VPNUsually leaves connection start and end recordsJudged against the tunnel device's own connection logs; application behavior inside the tunnel is recorded by each target system.
Open source bastionText and graphical session recording is commonJudged against the recording a community edition offers by default; the protocols it covers vary by implementation.
Commercial PAMMostly carries session recording and playbackJudged against the recording described in a product's public documentation; the protocols covered and the retention vary by licensed module.
CustodexaSSH, RDP, VNC, and the database console are recorded end to end and play backSpec:session-recording

Database statement auditing

ApproachCommon shapeReading criteria
SSH jump hostDatabase access mostly falls outside its reachJudged against what the login host itself can observe; the target database's own audit settings are counted separately.
VPNBounded at the network layer, with no parsing of application statementsJudged against the shape of a tunnel passing packets; separately deployed database audit appliances fall outside this.
Open source bastionDepends on the implementation; mostly covers some protocolsJudged against the database protocols a community edition supports by default; the coverage and statement granularity vary by implementation.
Commercial PAMDepends on the edition; some carry statement-level auditingJudged against the database module described in a product's public documentation, mostly a separately licensed item.
CustodexaDatabase statements are recorded before they run, and dangerous ones can be blocked as they happenSpec:db-query-console

Evidence packaging

ApproachCommon shapeReading criteria
SSH jump hostMostly assembled from logs by handJudged against the general practice of taking host logs as raw material and having people assemble an audit deliverable.
VPNConnection logs are assembled by handJudged against the connection logs the tunnel device emits; merging evidence across systems is carried by external tools.
Open source bastionMostly offers export of records and recordingsJudged against the export a community edition offers by default; whether integrity evidence comes with it varies by implementation.
Commercial PAMMostly offers reports and exportsJudged against the reporting described in a product's public documentation; the output format and its verifiability vary by product.
CustodexaOne ZIP holding a manifest and a signature, with per-file hashes that verify offlineSpec:audit-workflows

Offsite copies

ApproachCommon shapeReading criteria
SSH jump hostMostly carried by the backup mechanism already in placeJudged against host-level file backup, where audit evidence takes the same backup path as any other file.
VPNCarried by the log forwarding already in placeJudged against the general practice of forwarding connection logs to an external log system.
Open source bastionDepends on the implementation; some support object storageJudged against the storage backends a community edition can be configured with; the custody ledger and retrieval verification vary by implementation.
Commercial PAMDepends on the edition; mostly offers archiving optionsJudged against the archiving and retention described in a product's public documentation.
CustodexaUploads to S3-compatible or GCS object storage, with a custody ledgerSpec:evidence-offsite-storage

Credential rotation

ApproachCommon shapeReading criteria
SSH jump hostTarget account passwords are mostly maintained by handJudged against the general practice of administrators changing passwords themselves or writing their own scripts.
VPNTunnel accounts are mostly maintained by a directory serviceJudged against the tunnel's own user credentials; accounts on the target hosts fall outside its reach.
Open source bastionDepends on the implementation; mostly maintained by handJudged against what a community edition offers by default; scheduled password changes mostly belong to paid or plugin territory.
Commercial PAMMostly carries scheduled rotationJudged against the automatic rotation described in a product's public documentation; the target types covered vary by module.
CustodexaScheduled password rotation for Linux and Windows accounts, with a rotation evidence reportSpec:change-secret

Deployment shape

ApproachCommon shapeReading criteria
SSH jump hostOne login host exposed to the outsideJudged against the general shape where a single host carries all traffic in and out.
VPNA gateway appliance or a cloud serviceDescribes both common shapes together, a self-hosted gateway and a subscription service.
Open source bastionMostly a single self-hosted serviceJudged against the deployment a community edition's documentation suggests; clustered deployment varies by implementation.
Commercial PAMMostly an appliance or a subscription serviceJudged against the delivery shape described in a product's public documentation; where self-hosted and managed coexist, the common one is taken.
CustodexaLinux packages for two architectures with verified images and offline bundles; source deployment is also availableSpec:deployment-configuration

License

ApproachCommon shapeReading criteria
SSH jump hostFollows the license of the operating system components already in placeJudged against the remote login service shipped with the operating system, and excludes separately purchased add-ons.
VPNDepends on the implementation; open source and commercial both existDescribes the fact that both kinds of supply exist in the market, without pointing at any implementation.
Open source bastionMostly under an open source licenseJudged against the community edition whose source is public; the commercial edition of the same project carries its own terms.
Commercial PAMA commercial subscription or a perpetual licenseJudged against the general pricing shape of commercial products; the actual terms follow the contract.
CustodexaOpen source under AGPL-3.0, with source you can review yourselfSpec:release-snapshot

This page is not audit evidence in itself. To show an auditor the facts in the Custodexa column above, the evidence is on these pages: