> ## Documentation Index
> Fetch the complete documentation index at: https://docs.myrmex.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# CyberArk PAM (Self-Hosted)

> CyberArk Privileged Access Manager, self-hosted, over the PVWA REST API.

Connect **CyberArk Privileged Access Manager**, self-hosted, over the PVWA REST API. This is the on-premises privileged-credential Vault — distinct from [CyberArk Identity](/documentation/integrations/cyberark-identity), which is the IAM service.

## What Myrmex Can Do

<CardGroup cols={2}>
  <Card title="Safes and accounts" icon="list-check">
    Browse Safes and privileged accounts, and retrieve credentials — every retrieval audited.
  </Card>

  <Card title="CPM operations" icon="gauge">
    Change, verify and reconcile credentials.
  </Card>

  <Card title="Authorizations" icon="sliders">
    Grant and revoke Safe-member privileged access.
  </Card>

  <Card title="Vault administration" icon="shield-halved">
    Vault users, platforms and Application Access Manager apps.
  </Card>
</CardGroup>

## Before You Start

* A **Vault user**. Its Safe authorizations bound which Safes and accounts the agents can reach.
* A **Collector** that can reach it.

<Tip>
  Scope the credential to what Myrmex should reach. A narrower one still connects — it just leaves the agents with less reach.
</Tip>

## Add the Integration in Myrmex

From the **Directory**, choose **Add Integration → CyberArk PAM (Self-Hosted)**, then fill in:

| Field | Description |
| - | - |
| **Name** | A unique name for this instance. |
| **Description** | Optional note to identify it. |
| **Full URL** | The PVWA address the Collector can reach. |
| **Logon method** | `CyberArk` by default; the Vault's authentication method. |
| **Username / Password** | The Vault user. Its Safe authorizations bound what the agents can reach. |
| **Concurrent session** | Allow a concurrent session (`true` by default). |
| **Token** | A pre-issued session token, as an alternative to the logon. |
| **Verify ssl** | Validate the certificate (`true` by default). |
| **Collector** | The [Collector](/documentation/agent-endpoint-security/collector-mode) that reaches it. |

<Note>
  The integration is tied to the **context** you have selected when you create it.
</Note>

## Connect

Click **Connect** to validate and finish. It then appears in the **Directory**. New to integrations? See the [Integrations overview](/documentation/integrations/overview).
