T Techclick ← All lessons
CyberArk · Evidence desk · Interactive lesson

Prove CyberArk is working — first tool + proof field

01:40. Slack: “Is CyberArk even working? Why can’t they check out the password?” The Vault tile is green. A screenshot of a spinning RDP window is not proof. This desk is five official Privilege Cloud / PVWA tools — Accounts View / Safe members, Monitoring recordings, User and Safe Activities (User, Safe, Action), CPM Last Verified / Compliance Status, System Health — each mapped to one ticket, one first click, and one field you paste before you Change anything.

~20 min read · L2 primary · Quiz at end · Blog 1 · Factory

⚡ Quick Answer

How you prove CyberArk is working: PVWA Accounts / Safe ACL, PSM recordings, Vault audit User·Safe·Action, CPM verify/reconcile, connector health. Five tickets with first tool and one proof field.

After this page you can

Quick answer (say this out loud)

Accounts View / Safe members answers “is this identity even allowed to List or Retrieve this account?” Monitoring answers “did a PSM session start, and for which user + target?” User and Safe Activities answers “what Action hit this Safe — Retrieve password 295, PSM Connect 300, or Connect Failure 301?” Last Verified / Compliance Status answers “is the Vault password still the target password?” System Health answers “is this CPM / PSM connector Connected or Disconnected?” A green Vault is not a retrieve. A recording that never started is not “PSM is down.” A Change is not a reconcile.

1. Why “is it working?” is five questions

Operators collapse five failures into one sentence. The contractor is not a Safe member. Dual control is waiting on a confirmer. PSM never reached the target. The password on the box drifted from the Vault. The Privilege Cloud Connector dropped. Those are five first clicks.

This page is the night-shift desk for proof. The factory taught the objects — Safe, platform, CPM rotate versus reconcile, PSM, dual control. Here you learn the five tools you actually open, in order, when someone asks you to prove CyberArk is working — or why they cannot check out the password.

Hero · vault, session, Safe
Isometric night desk with a Vault door, a session-recording laptop, and a Safe box
Notice: three objects on one desk. The Vault door being closed does not prove the Safe ACL, and a session player with no file is not a connector outage.
Interview line

If they say “prove CyberArk is working,” do not say “I opened PVWA.” Say: “I prove the ACL with Safe members Retrieve accounts, the session with Monitoring user + target, the action with Activity log User / Safe / Action, the secret with Last Verified, and the plane with System Health Connectivity Status.”

2. Mental model — five proof tools

Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you Change a healthy secret at 02:00.

1 · Accounts / Safe ACL

Privilege Cloud Portal Accounts View, then Policies → Safes → Members. Proves List / Retrieve / Use. Does not prove the password on the target, or that PSM reached it.

2 · PSM recordings

Portal Monitoring. Proves a privileged session: User, Target Address, Connection Type, start, duration. Empty Monitoring often means no session ever started — not “PSM is down.”

3 · Vault / Privilege Cloud audit

Reports → Generate Report → Activity log (User and Safe Activities). Official output fields include Time, User, Action, Safe, Target, Reason, Alert.

4 · CPM verify / reconcile

Accounts View → account → Overview. Proves Last Verified and Compliance Status. Verify checks sync. Reconcile resets both sides. Change is a third verb.

5 · Connector health

System Health → CPM and Accounts Discovery / PSM. Proves App-user Connectivity Status Connected or Disconnected, plus active PSM sessions. A Connected CPM is not a retrieve.

Hard words, once

Retrieve = Show / Copy the password (needs Retrieve accounts). Use = Connect through PSM without viewing the secret. Check-out = exclusive lock. People say “check out” for all three — you name which one.

Flow 1 · five tools, one question each
Write user + Safe + account + UTC first · then pick the tool Is CyberArk working? five questions, not one Accounts / ACL Allowed to retrieve? List / Retrieve / Use Policies → Safes Members tab not a target sync Monitoring This PSM session? User · Target Address Connection Type Portal → Monitoring empty ≠ connector down Activity log What Action hit? User · Safe · Action 295 / 300 / 301 Reports → Generate not a hop latency CPM Overview Vault = target? Last Verified Compliance Status Accounts → Overview Change ≠ Reconcile System Health Connector alive? Connectivity Status CPM / PSM App users Portal → System Health not a Safe member Empty Accounts View is data. It usually means List accounts is missing — not that Privilege Cloud is down. Do not Change a password from an empty list. Start at Policies → Safes → Members.

Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing.

Say this out loud

I prove the ACL, then the session, then the Action code, then Last Verified, then the connector. I do not Change, Reconcile, or reset a connector App user until I can quote the field that made me do it.

3. Decision flow — ticket → first tool

Flowchart first. Do not open Change / Reconcile until a diamond says so.

Path · pick the branch before the menu
Ticket fork splitting into five CyberArk proof tiles: Safe ACL, session recording, audit, CPM gauge, connector health
Notice: the diamond is the ticket. The path is the tool. The field comes last. Do not reverse that order.
Flow 2 · first-tool diamond
Symptom first · tool second · field third What must we prove? Can they see it? or already inside? Invisible / denied Safes → Members Retrieve accounts PSM / RDP fail Monitoring User · Target Who did what? Activity log User · Safe · Action Wrong password Overview tab Last Verified Whole site dead System Health Connectivity Status Empty Accounts View for that user → stop. There is no 295 to chase. Fix membership or dual-control confirmation. Then re-open Show / Connect. Diamond = decision. Do not Change from the bottom box. Self-hosted operators still say PVWA. Privilege Cloud Portal is the same Accounts View / Safes / Monitoring / Reports / System Health surface.

Read the diamond first. An invisible Safe never starts in System Health. A drifted password never starts in Monitoring. “Whole site dead” never starts in Retrieve accounts.

4. How to choose — first tool + proof field

Print this next to the Privilege Cloud Portal. If you cannot recite the proof field, you are not ready to Change anything.

If the ticket says…First tool (official path)Proof fieldDo not open first
Cannot see the Safe / “can’t check out the password” Portal Accounts View, then Policies → Safes → Members Member present? List accounts / Retrieve accounts / Use accounts. Access request column if dual control. A manual Change, or System Health
PSM / RDP “CyberArk is down” for one user or one target Portal Monitoring (Recordings / Active Sessions) User + Target Address + Connection Type + start / duration. No row → session never started. A password Change
Who retrieved / connected / failed — audit or Sev-2 timeline Reports → Generate Report → Activity log (User and Safe Activities) Time, User, Action, Safe, Target, Reason, Alert (295 / 300 / 301) A Safe member add
Show works yesterday, Connect fails with a bad password / drift Accounts View → account → Overview Last Verified + Compliance Status (+ Status = Failed / Scheduled for Verification/Reconciliation) A connector reboot
Whole site / every PSM session dead after a network change Portal System Health → CPM and Accounts Discovery / PSM Component Connectivity Status Connected or Disconnected + active session count A Cloud / URL Allow, or a Safe ACL edit
“Check out” is three verbs (official)

People say “check out the password.” Official Privilege Cloud has three different controls. Retrieve is Show / Copy and needs Retrieve accounts. Use is Connect through PSM and needs Use accounts (the platform can hide the value). Check-out is exclusive access — the account shows Locked / lands in the Checked-out filter until the user checks it in or the minimum validity period expires and CPM rotates. Quote which verb failed. Do not disable exclusive access to “unstick” a retrieve.

5. Runbook Side A → B → C

Side A proves the person is allowed to see and retrieve the secret. Side B proves the session and the Action that hit the Safe. Side C proves the password still matches the target and the Connector is still talking. On a messy Sev-2, do them in this order until a field lights up.

Side A — Accounts View + Safe ACL (can they even retrieve?)

  1. Open Accounts View as the failing identity’s authorized list

    Path: Privilege Cloud Portal → Accounts View (this is the default after sign-in). Official: View accounts and account details. Filter All accounts. If the contractor cannot see Finance-Windows / 18_finance_admin, they do not have List accounts on that Safe. There is no password to Change.

  2. Read the grid columns that close an ACL ticket

    Status (dash = operational; icons = Disabled for passwords rotation, Locked, Platform inactive/deleted, Failed password management). Safe. Access request — a request waiting is dual control, not an outage. Address and Platform ID confirm you have the right object.

  3. Open the Safe Members tab, not the Vault widget

    Path: Policies → Safes → select the Safe → Members. Official: Manage Safe members. You need View Safe Members to read this. Quote whether the user or their AD group is a member, and whether List accounts, Retrieve accounts, and Use accounts are checked. Use without Retrieve is a legal Connect that still cannot Show.

  4. If Access request is populated, chase the confirmer

    Master Policy dual control + Safe permission Confirm requests. Access Safe without confirmation overrides the wait — that is a design exception, not a night-shift toggle. Audit codes 109 Get File Request, 37 Confirm Get File, 119 Reject Get File Request are the official trail.

lab.privilegecloud.cyberark.cloud · Policies → Safes → Finance-Windows → Members
Training mock · not live

Policies / Safes / Finance-Windows / Members

Safe members

Finance-Windows
Group
MemberTypeListRetrieveUseConfirm
Finance-AdminsGroupYesYesYesL1
contractor@lab.exampleUser

Source: CyberArk Docs — Manage Safe members; Safe permissions (List accounts, Use accounts, Retrieve accounts, Confirm requests). Lab identities only. Training mock · not live.

Side B — Monitoring + Activity log (did a session happen, what Action?)

  1. Open Monitoring, not Change

    Path: Privilege Cloud Portal → Monitoring. Official: Monitor sessions. The menu is hidden if there are zero recordings and zero sessions — that itself is data. Filter User + Target Address + date range. Session monitoring requires a PSM connector; SIA-only tenants do not get this grid.

  2. Read the session properties that close a PSM ticket

    Administrator-configured columns typically include the user who initiated, start time, duration, Target Address, Connection Type. Play Video is the recording. No row + user swears they clicked Connect → look at audit 301 PSM Connect Failure, not a password Change.

  3. Generate the Activity log and quote User, Safe, Action

    Path: Reports → Generate Report → Activity log (docs also call the same store User and Safe Activities). Default output fields: Time, User, Action, Safe, Target (account), Target Platform, Reason, Alert, RequestID, ClientID. Filter User + Safe + period.

  4. Memorise the three night-shift Action codes

    295 Retrieve password. 300 PSM Connect. 301 PSM Connect Failure (Alert). Sibling CPM codes you will meet on Side C: 22 Verify, 38 Verify Failure, 24 Change, 57 Change Failure, 31 Reconcile, 60 Reconcile Failure. Unauthorized retrieve is 42 / 43 Retrieve File (Unauthorized).

lab.privilegecloud.cyberark.cloud · Reports → Generate Report → Activity log
Training mock · not live

Reports / Generate Report / Activity log

User and Safe Activities

ops@lab.example
Finance-Windows
Last 1 hour
18_finance_admin
TimeUserActionSafeTargetAlert
01:38Zops@lab.example295 Retrieve passwordFinance-Windows18_finance_admin
01:39Zops@lab.example301 PSM Connect FailureFinance-Windows18_finance_adminAlert

Source: CyberArk Docs — Generate and view reports; Configure report settings (Activity log fields Time, User, Action, Safe, Target); Audit action codes 295 / 300 / 301. Lab identities only.

Activity log — fields you write in the ticket
Path:            Reports → Generate Report → Activity log
Filter:          User + Safe + period
Quote:           Time + User + Action + Safe + Target + Reason + Alert
Night codes:     295 Retrieve password
                 300 PSM Connect · 301 PSM Connect Failure
                 22 / 38 Verify · 24 / 57 Change · 31 / 60 Reconcile
If no 295:       they never retrieved — go back to Safe members

Side C — CPM Overview + System Health (is the secret true, is the Connector up?)

  1. Read Last Verified before you touch Change

    Path: Accounts View → click the account → Overview. Official: Manage and reconcile account passwords. Last Verified is whether the password on the target equals the password in Privilege Cloud. Click Verify (needs Initiate CPM account management operations). CPM verifies in the next management cycle; the compliance indicator updates when it finishes.

  2. Reconcile is the unsynchronized verb

    If Verify fails, the next official step is Reconcile on the same Overview Compliance Status pane — not a hopeful Change, and not “Change password only in the vault” unless you intend to split-brain the target. Reconcile uses the linked reconcile account. Change / Reconcile / Verify stay disabled until CPM finishes a reconcile. Operational Views filter: Scheduled for Change/Verification/Reconciliation, Successfully reconciled, Failed.

  3. Then — and only then — open System Health

    Path: Privilege Cloud Portal → System HealthCPM and Accounts Discovery or PSM. Official: Monitor system health. Proof field is component user Connectivity Status Connected or Disconnected, plus (for PSM) the count of currently active sessions. Disconnected is usually network or App-user sync, not a Safe ACL. Restoring CPM uses the SyncComponentUsers utility; restoring PSM needs Support to reset the App user — you cannot do that from the dashboard tile.

lab.privilegecloud.cyberark.cloud · Accounts View → 18_finance_admin → Overview
Training mock · not live

Accounts View / 18_finance_admin / Overview

Account overview

18_finance_admin
Finance-Windows · WinServerLocal
Failed password management
Failed · 01:12Z · code 38
18_finance_reconcile
01:39Z · ops@lab.example

Source: CyberArk Docs — View accounts and account details (Overview: Compliance Status, Last Verified, Activities); Manage and reconcile account passwords. Lab identities only.

Green success on each side

6. Five tickets as full stories

These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only: ops@lab.example, contractor@lab.example, Safe Finance-Windows, account 18_finance_admin, target 10.20.0.18.

Proof · named field, then Closed
Night operations desk with a verified check on one monitor and a highlighted audit row on the other
Notice: the close is a named column on a timestamp — Last Verified, or User + Safe + Action — not a screenshot of the user’s RDP window.
TicketSymptomFirst toolProof field
CEVD-01Contractor: “I can’t check out the finance password.” Vault widget green.Accounts View + Policies → Safes → MembersMember missing · List / Retrieve / Use accounts
CEVD-02Show is grey; Access request sitting since 18:00. “Portal is stuck.”Accounts View Access request + dual-control confirmerAccess request + audit 109 / 37 / 119
CEVD-03PSM RDP to 10.20.0.18 fails; L1 wants a Change.Monitoring, then Activity logNo recording row · Action 301 PSM Connect Failure
CEVD-04Connect fails after a local admin reset on the box. Yesterday worked.Accounts View → OverviewLast Verified failed · Compliance Status · code 38
CEVD-05Every PSM session in the site died after a 02:00 firewall change.System Health → PSM / CPMConnectivity Status = Disconnected

CEVD-01 — Prove the ACL (Accounts / Safe members)

01:42 · P2. New contractor authenticates to lab.privilegecloud.cyberark.cloud. Finance-Windows is invisible. Someone already “checked the Vault.” L1 drafted a Change on 18_finance_admin.

First tool: Accounts View as that user — empty for that Safe. Then Policies → Safes → Finance-Windows → Members.

Proof field: contractor@lab.example is not a member. Finance-Admins holds List + Retrieve + Use. The contractor was never added to the group. That is change-control — add the group (Manage Safe Members), do not Change the secret, do not reboot a Connector.

Trap

A colleague’s Accounts View is not proof. List accounts is per member. Predefined component users on the Safe (CPM, PSM) are not the contractor. Maximum 64 members including predefined users — do not “just add everyone.”

CEVD-02 — Prove the request (dual control, not a hang)

02:05 · P2. ops@lab.example can see the account. Show is waiting. Channel says “PVWA is stuck.” Someone wants Access Safe without confirmation flipped on the Safe.

First tool: Accounts View → Access request column, then the request details. Confirmers are Safe members with Confirm requests (level 1 / level 2 per Master Policy).

Proof field: request still open; audit 109 Get File Request at 18:04Z; no 37 Confirm Get File and no 115 Last Required Confirmation. That is a people queue. Chase the L1 confirmer. Disabling dual control is Master Policy / exception change-control, not isolate.

Close

I would not grant Vault Admins. I would quote the open request and the missing 37. After confirm, Show works for the request timeframe — then exclusive / one-time rules may rotate on check-in. That rotation is expected, not a second incident.

CEVD-03 — Prove the session (Monitoring + 301)

02:20 · P1. Finance on-call cannot RDP through PSM to 10.20.0.18. Vault tile green. L1 wants the password Changed “so PSM will work.”

First tool: Monitoring. Filter User = ops@lab.example, Target Address = 10.20.0.18, last hour. Grid is empty — or a zero-duration row. Session monitoring needs a PSM connector; if the tenant is SIA-only, this menu will not save you.

Proof field: Activity log 01:39Z · User ops@lab.example · Safe Finance-Windows · Action 301 PSM Connect Failure · Alert. There is a 295 one minute earlier — they retrieved, so the ACL is fine. A 301 after a 295 is a target / PSM path (NLA, AppLocker, connector) — not a Change. Factory lesson: Vault up ≠ authorized, and authorized ≠ connected.

Close

I would leave the password alone. I would paste User + Safe + Action 301 and the empty Monitoring row. Next isolate is the target RDP/NLA and the PSM connector, not Overview → Change.

CEVD-04 — Prove the secret (Last Verified / Reconcile)

02:40 · P2. Yesterday Connect worked. A local admin reset the password on 10.20.0.18 during a break-glass. Show still displays a value. Connect fails. L1 clicks Change twice.

First tool: Accounts View → 18_finance_adminOverview.

Proof field: Last Verified failed at 01:12Z. Compliance Status = Failed password management. Activities show CPM Verify Password Failure (38). Status filter Failed lists the same object. Official next click is Reconcile (linked reconcile account 18_finance_reconcile), not another Change, and not “Change password only in the vault” — that writes a new Vault value and leaves the target still drifted.

Trap

Verify / Change / Reconcile stay disabled until the in-flight reconcile finishes. Clicking Change again is not faster. No linked reconcile account → that is a platform / account-link gap, not a night-shift improvisation. You need Initiate CPM account management operations to press the button.

CEVD-05 — Prove the Connector (System Health)

03:00 · P1. Every PSM session in the Pune site died after a 02:00 firewall change. Accounts View still lists accounts. Someone typed Sev-1 “Vault is down.”

First tool: System Health → PSM (and CPM and Accounts Discovery on the same dashboard).

Proof field: PSM App user Connectivity Status = Disconnected since 02:01Z. Active sessions = 0. CPM on the same Connector may also show Disconnected. Official restore is not a Safe member add and not a password Change. CPM: SyncComponentUsers on the Connector. PSM: Technical Support resets the App user; you rebuild psmapp.cred / psmgw.cred with CreateCredFile, then confirm the tile returns Connected. Also confirm 443 to *.privilegecloud.cyberark.cloud is not TLS-inspected — the Connector pins the CyberArk chain.

Close

I would leave every Safe ACL alone. I would paste Connectivity Status + the 02:00 firewall change. After Connected returns, I want one Monitoring session and one 300, not a tenant-wide Change.

7. Traps + close-the-ticket proof

You seeWeak closeStrong close
Green Vault / green Portal login“CyberArk is working”You proved authentication. Open Accounts View + Members for that Safe.
Empty Accounts View for the userChange the password / restart CPMQuote missing member or missing List accounts. Add the group via change-control.
Use = Yes, Retrieve = No“Show is broken”By design they can Connect and cannot view. Quote the two permissions.
Access request sittingDisable dual control / grant Vault AdminsQuote the open request + missing 37. Chase the confirmer.
Empty Monitoring“PSM is down” / Change the secretEmpty often means the session never started. Read Action 301.
295 then 301Change, because retrieve “worked”ACL is fine. Isolate target / PSM path. Factory: authorized ≠ connected.
Last Verified failedChange, or Change only in the vaultReconcile with the linked account. Quote 38 then 31.
System Health DisconnectedAdd everyone to the SafeQuote Connectivity Status. Restore the Connector App user. Recheck the tile.
Locked / Checked-outUnlock for the whole SafeExclusive access. Check-in, or wait MinValidityPeriod. Unlock accounts is a specific permission — treat it as change-control.
Proof checklist before you leave the bridge
Interview close

I name the question, then the first tool, then one official field. Safe members prove the retrieve. Monitoring proves the session. Activity log proves User, Safe, Action. Last Verified proves the secret. System Health proves the Connector. I do not Change, Reconcile, or reset an App user until that field is on the ticket. Factory model: Vault up ≠ authorized.

Knowledge check

Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

Q1

Contractor: “I can’t check out the finance password.” Vault widget is green. You have not opened a Change yet. First proof?

Correct: b. Empty Accounts View is an ACL. Official path is Accounts View then Safes → Members. Re-read Side A and CEVD-01.
Q2

Show is waiting. Accounts View Access request has been sitting since 18:00. Which proof field closes CEVD-02?

Correct: a. Dual control is a people queue. Official codes 109 / 37 / 119. Do not flip Access Safe without confirmation at 02:00. Re-read Side A step 4 and CEVD-02.
Q3

PSM RDP to 10.20.0.18 fails at 01:39. Activity log already shows 295 Retrieve password for that user. First tool + field?

Correct: c. 295 means the ACL already allowed retrieve. 301 is the session. Empty Monitoring is expected if the session never started. Re-read Side B and CEVD-03.
Q4

You must prove who touched 18_finance_admin in Finance-Windows. Official report + fields?

Correct: b. Official Activity log (User and Safe Activities) default fields include Time, User, Action, Safe, Target. Re-read Side B steps 3–4.
Q5

A local admin reset the target password. Overview Last Verified failed (code 38). What do you do first?

Correct: d. Official next step after a failed verify is Reconcile, not a vault-only Change. Re-read Side C steps 1–2 and CEVD-04.
Q6

System Health shows the site PSM App user Connectivity Status = Disconnected since a 02:00 firewall change. What is that sentence allowed to mean?

Correct: a. Official System Health field is Connectivity Status. Restore is SyncComponentUsers / Support + CreateCredFile — not an ACL edit. Re-read Side C step 3 and CEVD-05.

Sources

Related: Blog 1 · CyberArk session factory — Vault up ≠ authorized · Privilege Cloud implementation · CyberArk practice dashboard