Video and Evidence Behind Your Access Policy
CyberArk built its business on privileged access, vaulting the credentials that reach the systems an organization cannot afford to lose. CyberArk Identity, the workforce product formerly sold as Centrify, applies that habit to everyone else, with one sign-in and an adaptive policy that asks for more proof when the request looks unusual. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026. Where a security team already treats identity as a control rather than a convenience, connecting Nexus extends that control to recordings, footage and case files, and to the Redactor, AI Intelligence Hub and AI Live Insight enabled on that portal.
How it connects
Sign-in is a redirect. The portal is added as an application in CyberArk Identity and, on the portal side, as an SSO app under Admin, Portal Settings, Apps carrying the provider's metadata address or a client id and secret, which the catalog labels SAML / OIDC. Whatever adaptive policy applies runs before they reach the portal: an authenticator app, a security key, a smartcard, or a step-up because the device or network is unfamiliar. Attribute mapping turns the returned claims into profile fields.
Provisioning is the second connection, with the portal as the SCIM 2.0 service provider. An administrator enables provisioning, generates a portal-scoped API token with an expiry, and gives CyberArk Identity that token and the base URI. Users and groups are pushed ahead of first sign-in, each on a Client Access License, the portal's bundle of features and permissions, from a default that rules override by matching the incoming group's display name, first match winning. Which groups are in scope is decided in CyberArk Identity, not in the portal.
The rest is what the portal does not get. The password never reaches it, nothing is written back, and force login leaves no local sign-in form to find. The portal's own second factor is an email passcode, which enforced SSO makes beside the point, since the stronger factors are the ones CyberArk Identity runs. The API token is itself a credential with an expiry, so it belongs in the rotation schedule the security team keeps.
What you can do together
Step-up policy reaches the evidence
The same conditions that guard a finance system now guard the recordings and case files in Nexus, with no separate policy to write or review.
One account, four products
Redactor, AI Intelligence Hub and AI Live Insight are enabled on that portal and inherit the same sign-in.
Entitlement and off-boarding stay upstream
Rules on the incoming group's display name set the Client Access License, and disabling the CyberArk Identity account deactivates the portal account, so both stay where the security team reviews them.
The assistant cannot exceed the user
AI Intelligence Hub runs retrieval under the asking person's own token, so an answer never reaches content they could not open by searching.
A scenario
- Week oneThe identity administrator adds the application in CyberArk Identity and the SSO app in Nexus, maps name, email and department, enables SCIM and sets two rules: Privacy Office to a reviewer Client Access License, everyone else to the viewer default.
- Monday, 06:50A charge nurse opens the training library from a ward workstation. CyberArk Identity takes her password, adds an authenticator code because the device is new to her, and returns her with a profile filled in.
- TuesdayA privacy officer opens Redactor to blur other patients from a corridor recording before release. The original stays untouched.
- Wednesday, 22:10A security supervisor reviews an AI Live Insight alert from the emergency department entrance. Signing in from home triggered the step-up rule the policy applies off the hospital network.
- Month endA resident's rotation ends and her CyberArk Identity account is disabled. The portal account deactivates with it, and force login means there is no local form to try.
What stays where
CyberArk Identity remains the identity provider
Passwords, adaptive factors and the account lifecycle are governed there, under the policy your security team owns.
Policy is not duplicated in the portal
There is no second place where an access rule is written, which is the point of connecting the two.
The flow is inbound
Claims arrive at sign-in, SCIM pushes users and groups, and nothing goes back to CyberArk Identity.
Deployment is a separate decision
Shared SaaS, a dedicated cloud, or your own datacenter at an address the provider can reach for provisioning.
Products and solutions
- Nexus, AI Intelligence Hub, AI Live Insight and Redactor
- Enterprise Video Platform, Video Training Platform and Secure Video Sharing
Next step
See it on your own CyberArk Identity instance. We will show the connection made, the data moving and the output, then size it for your deployment.
Request a demonstration or write to sales@vidizmo.ai
sales@vidizmo.ai · vidizmo.ai/integrations/catalog/cyberark-identity