Privileged access management
Also known as PAM
Controlling, monitoring, and recording the use of accounts that hold elevated rights.
PAM covers vaulting credentials so nobody knows the actual password, brokering sessions so access is proxied and recorded, rotating secrets automatically, and requiring approval for sensitive operations.
For smaller organizations the practical core is simpler: separate administrative accounts from daily-use accounts, unique passwords per system, and MFA on every one of them.
Where this comes up
Privileged access management sits inside our identity and access work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.