Skip to main content

Company News

Syteca Expands the Platform with PEDM and Endpoint Risk and Compliance Control (ERCC)

Share:

Admin rights and misconfigured endpoints are two of the easiest ways for risk to enter your organization and two of the hardest challenges to control without slowing people down. Today, Syteca expands its inside security platform with two new products: Syteca Endpoint Risk and Compliance Control (ERCC) and Privilege Elevation and Delegation Management (PEDM).

PEDM brings endpoint privilege management to Windows workstations and servers, allowing users to receive administrator rights only for approved tasks, under clearly defined rules. Syteca ERCC delivers continuous compliance monitoring, endpoint risk visibility, AI governance, and guided remediation to help your organization identify security gaps before they become attack paths.

New functionalities at a glance

PEDM can help your organization enforce least privilege without interrupting daily work. Instead of keeping users as permanent local administrators or routing every request through IT, your team can now define exactly which actions receive elevated access, when, and under what conditions.

Syteca ERCC gives your security and IT teams a clearer view of endpoint security and compliance gaps across your environment. It continuously evaluates device configurations, security controls, AI tool use, and policy adherence, then prioritizes what needs attention.

What’s new on the Syteca Inside Security Platform

Privilege Elevation and Delegation Management (PEDM)

  • Implement just-in-time admin rights to reduce exposure
  • Enforce least privilege without blocking legitimate work
  • Automate trusted elevation and govern sensitive requests
  • Block unapproved applications from running with elevated rights
  • Require user justification and approver validation for sensitive actions
  • Keep a complete audit trail of privilege elevation decisions

Endpoint Risk and Compliance Control (ERCC)

  • Continuously monitor endpoint health and catch configuration drift
  • Score risk for every endpoint and department
  • Run automated compliance checks
  • Detect AI tools and flag out-of-policy usage
  • Fix every finding with step-by-step remediation guidance
  • Flag endpoints connecting from high-risk regions

Our customers already rely on Syteca to control privileged access and gain visibility into what happens during critical sessions. With PEDM and ERCC, we are extending that control directly to the endpoint, governing which actions get elevated privileges and helping teams identify security or compliance gaps before they lead to incidents. And because both products run on the same lightweight agent and management console, customers can activate the protection they need without adding new operational complexity.

Oleg Shomonko, CEO at Syteca

Together, the new products extend Syteca’s security controls beyond privileged access and into the endpoint itself. Customers can now manage privileged access, monitor sessions, detect identity threats, control elevation, and assess endpoint security posture through a single unified platform.

What Syteca PEDM solves

Enforce least privilege

Eliminate IT bottlenecks

Reduce the attack surface

Get a full audit trail

Organizations often face an uncomfortable choice: keep users as local administrators and accept greater exposure, or restrict administrator access, which can create delays for employees and IT teams. PEDM removes that trade-off.

With Syteca, you can now remove local admin rights while still allowing employees, support teams, and other approved users to complete legitimate administrative tasks. Access is granted for a specific action, for a limited time, and according to the policies defined by the security team.

How Syteca PEDM works

1. Action

A user starts an application, installer, script, or other action that requires administrator rights.

2. Policy check

Syteca PEDM evaluates the request against the rules defined by your security team.

3. Access decision

Based on the policy, Syteca automatically elevates a trusted action, routes a sensitive request for approval, or blocks an unapproved or risky action.

4. Activity record

Syteca logs every approval and denial decision in the audit trail. When enabled, elevated activity can also be recorded to support investigations and compliance reviews.

PEDM helps turn ad-hoc “run as admin” requests into a governed, auditable workflow. It reduces the attack surface created by standing privileges while keeping routine software installation, updates, support, and troubleshooting work moving.

Syteca PEDM allows you to:

Support just-in-time elevation: Provide administrator rights only for the approved task and duration, instead of leaving privileged access in place.

Silently elevate trusted applications: Automatically allow approved applications to run with elevated rights based on policy, optionally limited to specific days, hours, or business periods.

Route sensitive actions for approval: Require users to provide a justification, notify approvers by email, and have approved applications launched through Syteca Access Center.

Block unauthorized software: Stop unapproved applications from gaining elevated access and provide users with a clear custom message explaining the next step.

Target rules with precision: Create rules based on file hash, executable name, path prefix, digital signature, or command-line parameters.

Use vaulted credentials: Run approved actions under securely stored credentials managed by Syteca’s workforce password manager.

Maintain complete visibility: Log every allow, approval, and denial decision, with optional recording of elevated sessions for deeper investigation.

How Syteca ERCC protects endpoints

Identify security gaps early

Govern AI tool use

Detect compliance misalignments

Focus remediation efforts

Security controls can be disabled, configurations can change, and unapproved tools can appear on endpoints without anyone noticing. In many cases, your organization may only discover these gaps during an audit or after an incident.

Syteca ERCC continuously checks endpoints for risks that make attacks possible in the first place. It can help your team identify configuration drift across operating system settings, security controls, registry values, services, and policies while the issue is still easy to address.

How Syteca ERCC works

1. Data collection

A lightweight Syteca agent continuously gathers endpoint data from OS settings, security controls, registry entries, services, and policies.

2. Risk assessment

Syteca analyzes security indicators to calculate an endpoint health score and prioritize the most important findings.

3. Compliance evaluation

The platform checks endpoint configurations against applicable compliance requirements, corporate policies, and AI usage rules.

4. Remediation guidance

For every detected issue, Syteca provides prioritized, step-by-step remediation guidance on what needs attention and how to resolve it.

As a key pillar of continuous controls monitoring (CCM), Syteca ERCC also supports broader governance, risk, and compliance (GRC) initiatives. With Syteca ERCC, your team can assess endpoint compliance against applicable SOC 2 core criteria, corporate security baselines, AI usage policies, and other organization-defined directives that can be validated through endpoint telemetry.

Syteca ERCC allows you to:

Run automated compliance checks: Continuously assess compliance with SOC 2 requirements verifiable by endpoint telemetry, corporate security baselines, and your AI usage policies.

Monitor endpoint health: Track security controls, OS settings, registry values, and services across endpoints to identify policy gaps.

Detect AI tools in use: Discover desktop applications, browser extensions, IDE plugins, agents, and chatbots, then flag activity that falls outside your policies.

Score risk by endpoint and department: Review transparent risk scores and see every factor contributing to the score result.

Guide teams through remediation: Receive step-by-step fixes for every finding in plain language with actions prioritized based on severity.

Enforce geolocation policies: Detect endpoints connecting from sanctioned or high-risk regions.

Surface deep-dive telemetry: Bring together antivirus status, browser extensions, registry settings, resource usage, and other endpoint data in one up-to-date view.

How PEDM and ERCC work together

Syteca PEDM answers a practical access question: Who can run what with administrator rights, when, and under which rules?

Syteca ERCC answers an equally important security question: Is this endpoint secure and meets organizational policies?

Together with Syteca’s privileged access management (PAM), workforce password management, session monitoring, and identity threat detection and response (ITDR) capabilities, these products give organizations deeper control over privileged activity and endpoint risk. 

PAM and session monitoring help understand who accessed a system and what they did; PEDM governs privileged actions on the device; Syteca ERCC helps verify that the device itself remains securely configured.

One platform: Choose the capabilities you need

One agent

One console

One audit trail

Syteca brings multiple inside security capabilities together in one platform. Instead of deploying separate tools for each use case, you can roll out the platform once and enable the products that align with your current security priorities through licensing.

Available Syteca products

Privileged access management

Identity threat detection and response

Workforce password management

Session monitoring

Privilege elevation and delegation management

Endpoint risk and compliance control

All products operate through the same lightweight agent and centralized management console. This unified approach helps your team reduce deployment and administration overhead while maintaining consistent visibility and a connected audit trail across privileged access, identity activity, and endpoint security.

Get started with Syteca PEDM and ERCC

Syteca continues to evolve to help you reduce risk without adding unnecessary complexity. With PEDM and ERCC, security and IT teams can enforce least privilege, identify endpoint gaps earlier, improve compliance readiness, and maintain stronger oversight of their endpoint environment.

Already using Syteca? Contact your account manager to activate Syteca ERCC and PEDM.

Share:

Content

See how Syteca can enhance your data protection from insider risks.