Your quarterly access review is a spreadsheet nobody readsAuditors want to know why each grant exists

Analyses every identity, role, policy and key against 31 criteria, cites the PCI requirement each finding affects, and hands back a triaged worklist, with a compliance score an assessor can reproduce by hand.

Try it

Interactive demo with a completed review, no signup, no cloud account

How It Works

Discover, collect, analyse, evidence.

01

Discover

Every account the organisation owns is discovered and each session validated against the expected account before anything is collected. A mismatch stops the run rather than producing a partial report.

02

Collect

Users, roles, policies, groups, access keys, MFA devices and the credential report, gathered read-only with short-lived credentials.

03

Analyse

Thirty-one criteria across identities, roles, policies and keys, from directly attached administrative access to trust policies that accept an external account root without a condition.

04

Evidence

A sixteen-section report with a management sign-off block, every finding cited to its PCI requirement and triaged into modify, revoke or add.

What You Can Do

Everything the review does.

Thirty-one published criteria

Twelve for identities, eight for roles, six for policies and five for access keys, listed in the product, so you know exactly what was assessed and what was not.

See it in the demo

A score you can check by hand

100 minus 15 per critical, 8 per high, 3 per medium and 1 per low, floored at zero, with three named bands. The arithmetic is printed under the number rather than hidden behind a model.

See it in the demo

Multi-account, or it does not run

Every account is discovered and every session identity validated before collection. Silent partial coverage produces a report that looks complete and is not, so the run fails closed instead.

See it in the demo

Humans and service accounts together

Console users and machine identities are assessed in one pass, with never-logged-in service accounts handled as a first-class case rather than as missing data.

See it in the demo

Every finding is a work item

Each carries modify, revoke or add alongside its severity, so the report is a triaged worklist. Everything to revoke this afternoon filters apart from everything to document this quarter.

See it in the demo

Findings name the credential

Not "credential hygiene needs attention" but the identity, the key and its age, specific enough to verify, dispute or fix without a follow-up conversation.

See it in the demo

Trust policies are read, not counted

Roles trusting an external account root without an ExternalId, and federated roles missing a subject condition, are attack paths a role inventory would never surface. Both are detected and shown in full.

See it in the demo

Governance gaps are graded

Missing owners, descriptions and business justification are what assessors actually fail you on. They are scored alongside the permission problems rather than omitted for being unglamorous.

See it in the demo

Every finding cites its requirement

Each requirement carries a status, the evidence behind it and the remediation, so the review drops into a PCI assessment or a SOC 2 access recertification without being rewritten.

See it in the demo

Least privilege measured against usage

Effective permissions are compared with observed access, so an administrative grant used for three services is reported as roughly ten times wider than the need rather than simply flagged as admin.

See it in the demo

Auditor-ready deliverable

A sixteen-section document in Word, PDF and Markdown with dedicated modify, revoke and add sections and a management sign-off block for the audit trail.

See it in the demo

Read-only by construction

Requires only list and get permissions, runs on short-lived credentials, and never writes them to outputs, logs or reports.

See it in the demo

Business Outcomes

What it changes.

Actionable

A triaged worklist with an action verdict per finding, rather than a spreadsheet that gets signed and filed without anything changing.

Defensible

A published scoring formula and a cited requirement per finding, so the review survives contact with an assessor.

Complete

Every account, every identity, every trust policy, with the run failing closed rather than quietly reviewing one account and calling it done.

See who can actually reach what.

Connect a read-only role and the first review returns a triaged worklist in minutes.