VIDIZMO integration brief · CyberArk Identity · vidizmo.ai/integrations/catalog/cyberark-identity

Integrations / CyberArk Identity

CyberArk Identity

Sign users in with CyberArk Identity. Visit website

CyberArk Identity is the workforce identity product formerly sold as Centrify, providing single sign-on and adaptive multi-factor authentication.

CyberArk Identity stays the identity provider and the platform never becomes one. Accounts, password policy and multi-factor stay where they are already governed, and access is removed by disabling the account there.

Video and Evidence Behind Your Access Policy

Open as a two-page brief

CyberArk built its business on privileged access, vaulting the credentials that reach the systems an organization cannot afford to lose. CyberArk Identity, the workforce product formerly sold as Centrify, applies that habit to everyone else, with one sign-in and an adaptive policy that asks for more proof when the request looks unusual. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026. Where a security team already treats identity as a control rather than a convenience, connecting Nexus extends that control to recordings, footage and case files, and to the Redactor, AI Intelligence Hub and AI Live Insight enabled on that portal.

How it connects

Sign-in is a redirect. The portal is added as an application in CyberArk Identity and, on the portal side, as an SSO app under Admin, Portal Settings, Apps carrying the provider's metadata address or a client id and secret, which the catalog labels SAML / OIDC. Whatever adaptive policy applies runs before they reach the portal: an authenticator app, a security key, a smartcard, or a step-up because the device or network is unfamiliar. Attribute mapping turns the returned claims into profile fields.

Provisioning is the second connection, with the portal as the SCIM 2.0 service provider. An administrator enables provisioning, generates a portal-scoped API token with an expiry, and gives CyberArk Identity that token and the base URI. Users and groups are pushed ahead of first sign-in, each on a Client Access License, the portal's bundle of features and permissions, from a default that rules override by matching the incoming group's display name, first match winning. Which groups are in scope is decided in CyberArk Identity, not in the portal.

The rest is what the portal does not get. The password never reaches it, nothing is written back, and force login leaves no local sign-in form to find. The portal's own second factor is an email passcode, which enforced SSO makes beside the point, since the stronger factors are the ones CyberArk Identity runs. The API token is itself a credential with an expiry, so it belongs in the rotation schedule the security team keeps.

What you can do together

01

Step-up policy reaches the evidence

The same conditions that guard a finance system now guard the recordings and case files in Nexus, with no separate policy to write or review.

02

One account, four products

Redactor, AI Intelligence Hub and AI Live Insight are enabled on that portal and inherit the same sign-in.

03

Entitlement and off-boarding stay upstream

Rules on the incoming group's display name set the Client Access License, and disabling the CyberArk Identity account deactivates the portal account, so both stay where the security team reviews them.

04

The assistant cannot exceed the user

AI Intelligence Hub runs retrieval under the asking person's own token, so an answer never reaches content they could not open by searching.

A scenario

  1. Week oneThe identity administrator adds the application in CyberArk Identity and the SSO app in Nexus, maps name, email and department, enables SCIM and sets two rules: Privacy Office to a reviewer Client Access License, everyone else to the viewer default.
  2. Monday, 06:50A charge nurse opens the training library from a ward workstation. CyberArk Identity takes her password, adds an authenticator code because the device is new to her, and returns her with a profile filled in.
  3. TuesdayA privacy officer opens Redactor to blur other patients from a corridor recording before release. The original stays untouched.
  4. Wednesday, 22:10A security supervisor reviews an AI Live Insight alert from the emergency department entrance. Signing in from home triggered the step-up rule the policy applies off the hospital network.
  5. Month endA resident's rotation ends and her CyberArk Identity account is disabled. The portal account deactivates with it, and force login means there is no local form to try.

What stays where

CyberArk Identity remains the identity provider

Passwords, adaptive factors and the account lifecycle are governed there, under the policy your security team owns.

Policy is not duplicated in the portal

There is no second place where an access rule is written, which is the point of connecting the two.

The flow is inbound

Claims arrive at sign-in, SCIM pushes users and groups, and nothing goes back to CyberArk Identity.

Deployment is a separate decision

Shared SaaS, a dedicated cloud, or your own datacenter at an address the provider can reach for provisioning.

Products and solutions

Next step

See it on your own CyberArk Identity instance. We will show the connection made, the data moving and the output, then size it for your deployment.

Request a demonstration  or write to sales@vidizmo.ai

sales@vidizmo.ai  ·  vidizmo.ai/integrations/catalog/cyberark-identity

Not what you need?

We build it

Send us your API documentation and we build, test and maintain the connector, at no development cost to you.

Request this integration

Bring an MCP server

If the system publishes a Model Context Protocol server, AI Intelligence Hub connects to it as a client with configuration alone.

Define a REST endpoint

Describe your endpoint and it becomes a node in an agent workflow, without waiting on our roadmap.