← Back to all sparks
B

Bitwarden

DEVOPS
Velocity5.0

Open-source password manager for individuals and teams.

Bitwarden is building toward privileged access management with PAM access claims and access rules infrastructure landing in v2026.8.

privileged-accessenterprise-securityaccess-rulespassword-managementopen-sourcepam
Current state
Bitwarden's server releases follow a monthly cadence with gradual feature rollout via feature flags. The most directional recent work is in v2026.8.1: PAM access claims and a ManageAccessRules permission type are being added to the server, and an Access Rules system with domain-level persistence and schema is under construction. This is adjacent-but-different from password management — PAM covers privileged credentials, session recording, and policy-gated access. The adjacent v2026.8.0 work (role-escalation validation in org user updates, managed-device-framework flag) follows the same enterprise hardening pattern.
Where it's heading
Bitwarden is expanding from a credentials store toward a policy-managed access control platform. The recent release stream shows a consistent pattern: removing feature flags for shipped capabilities (pricing migration, policy enforcement, consolidated session timeout) while adding new scaffolding for PAM, managed device frameworks, and access rule engines. This is the architecture of a company moving up-market from SMB password management to enterprise privileged access.
Prediction
A dedicated PAM product tier or the full public launch of Access Rules is likely in the next two major releases; the current work is clearly pre-GA scaffolding, not a finished feature.

Recent moves

  1. 7d ago

    Version 2026.8.2

    v2026.8.2 is a two-change patch: a route parameter enforcement fix and a version bump — pure maintenance with no user-facing change.

    View source ↗
  2. 14d ago

    Version 2026.8.1

    v2026.8.1 adds PAM access claims and a ManageAccessRules permission to the server, alongside Access Rules domain/persistence/schema work — groundwork for a privileged access management capability that would expand Bitwarden's scope beyond password storage.

    View source ↗
  3. 28d ago

    Version 2026.8.0

    v2026.8.0 adds role-escalation validation in the v2 UpdateOrganizationUser command, admin-initiated member email changes, and a managed-device-framework feature flag — enterprise access control hardening across org user management.

    View source ↗
  4. 1mo ago

    Version 2026.7.2

    v2026.7.2 removes feature flags for policy enforcement and pricing migrations (shipping those features to all users) and adds verified-email enforcement for organization invite links — progressive rollout completing.

    View source ↗
  5. 1mo ago

    Version 2026.7.1

    v2026.7.1 is a single-fix patch for a billing schedule rewrite issue affecting plan-migration organizations — a targeted regression fix.

    View source ↗
  6. 1mo ago

    Version 2026.7.0

    v2026.7.0 adds name and email to org user update endpoints, Teams 2019 plan migration support, and admin-initiated member email change scaffolding behind a feature flag — continued org management and pricing migration work.

    View source ↗