Blog

Orchid and Idira Bring Hidden Privileged Identities Into View

August 2, 2026

7 min read

Posted by
Naveh Dayan
Tech Product Manager
On this page
Getting your Trinity Audio player ready...

Our new technical alliance connects Orchid's identity discovery and analysis with Idira's native privileged access workflow.

Every privileged access management program has a boundary: it can only manage the identities it knows about.

That boundary is becoming harder to define. Enterprise identity now extends far beyond employees and traditional administrators. Humans, service accounts, machine identities, API integrations, and AI agents all authenticate, receive permissions, and act across the business. Many of those identities remain outside the centralized systems designed to govern them.

The result is identity dark matter: active identities, credentials, and access paths that carry real privilege but remain unseen and unmanaged.

Today, we're announcing a new technical alliance with Palo Alto Networks and the availability of Orchid's integration with Palo Alto Networks Idira®, the new name of the CyberArk brand. Together, we're connecting Orchid's ability to discover and analyze identity with the privileged access workflows security teams already operate in Idira.

Finding privilege that traditional inventories miss

Privileged access is not always attached to an obvious administrator account. It can belong to a local user inside a business application, a service account running a critical process, a machine identity connected to infrastructure, or a credential used by an automated system.

Orchid continuously discovers accounts, identities, and authentication flows across managed and unmanaged environments. It analyzes how authentication and authorization are actually implemented, correlating roles, permissions, account types, ownership signals, and system context. This allows Orchid to identify accounts with privileged access even when they do not appear in an identity provider, IGA platform, or PAM inventory.

That distinction matters. A list of known privileged accounts can only describe the identities that have already entered the governance process. Orchid helps reveal the ones that have not.

Connecting identity insight to privileged access action

With the new integration, security teams can report an Orchid-identified privileged account directly to the Discovered Accounts queue in Idira Privilege Cloud. The account arrives with Orchid as its source and with the context needed to understand where it was found and why it requires privileged access review.

Idira administrators can then assess the account and decide whether and how to onboard it through their established PAM process. Orchid records that the account was reported, giving teams a clear connection between discovery and action.

Orchid does not send credential values, secrets, or session data. It does not write to the vault or alter credentials. Onboarding, vaulting, rotation, and ongoing management remain under the control of the Idira administrator.

This gives customers broader coverage without changing the way their privileged access program operates. Orchid expands visibility and adds identity context. Idira remains the system where privileged access decisions are reviewed and managed.

Privilege now spans humans, non-human identities, and AI agents

The definition of a privileged identity is changing.

Human administrators are still critical, but they are no longer the only identities with consequential access. Non-human identities such as service accounts, workload identities, API keys, bots, and automation pipelines often hold broad, standing permissions. Their ownership can be unclear, and their lifecycle rarely follows the joiner, mover, and leaver processes built for employees.

AI agents introduce another identity class. They can reason, select tools, and act across multiple systems using authority delegated by a person or another system. This combines human-like adaptability with machine speed and scale. If an agent encounters an unmanaged local account, an overprivileged service identity, or an ungoverned access path, existing identity gaps can quickly become agentic risk.

Securing this new landscape starts with strong identity fundamentals: discover what exists, understand who or what each identity represents, identify where privilege resides, and bring that privilege into the right governance and control workflows.

That is where Orchid and Idira come together.

This integration is a practical step toward a broader goal: helping enterprises govern privilege across human, non-human, and agentic identities. It also creates a foundation for additional use cases that connect Orchid's identity discovery and context with Idira's governance and control. By identifying hidden privilege and bringing it into tools security teams already trust, Orchid helps turn identity dark matter into manageable risk.

See Orchid in action.