Thirty-one published criteria
Twelve for identities, eight for roles, six for policies and five for access keys, listed in the product, so you know exactly what was assessed and what was not.
See it in the demoAnalyses every identity, role, policy and key against 31 criteria, cites the PCI requirement each finding affects, and hands back a triaged worklist, with a compliance score an assessor can reproduce by hand.
Interactive demo with a completed review, no signup, no cloud account
01
Every account the organisation owns is discovered and each session validated against the expected account before anything is collected. A mismatch stops the run rather than producing a partial report.
02
Users, roles, policies, groups, access keys, MFA devices and the credential report, gathered read-only with short-lived credentials.
03
Thirty-one criteria across identities, roles, policies and keys, from directly attached administrative access to trust policies that accept an external account root without a condition.
04
A sixteen-section report with a management sign-off block, every finding cited to its PCI requirement and triaged into modify, revoke or add.
What You Can Do
Twelve for identities, eight for roles, six for policies and five for access keys, listed in the product, so you know exactly what was assessed and what was not.
See it in the demo100 minus 15 per critical, 8 per high, 3 per medium and 1 per low, floored at zero, with three named bands. The arithmetic is printed under the number rather than hidden behind a model.
See it in the demoEvery account is discovered and every session identity validated before collection. Silent partial coverage produces a report that looks complete and is not, so the run fails closed instead.
See it in the demoConsole users and machine identities are assessed in one pass, with never-logged-in service accounts handled as a first-class case rather than as missing data.
See it in the demoEach carries modify, revoke or add alongside its severity, so the report is a triaged worklist. Everything to revoke this afternoon filters apart from everything to document this quarter.
See it in the demoNot "credential hygiene needs attention" but the identity, the key and its age, specific enough to verify, dispute or fix without a follow-up conversation.
See it in the demoRoles trusting an external account root without an ExternalId, and federated roles missing a subject condition, are attack paths a role inventory would never surface. Both are detected and shown in full.
See it in the demoMissing owners, descriptions and business justification are what assessors actually fail you on. They are scored alongside the permission problems rather than omitted for being unglamorous.
See it in the demoEach requirement carries a status, the evidence behind it and the remediation, so the review drops into a PCI assessment or a SOC 2 access recertification without being rewritten.
See it in the demoEffective permissions are compared with observed access, so an administrative grant used for three services is reported as roughly ten times wider than the need rather than simply flagged as admin.
See it in the demoA sixteen-section document in Word, PDF and Markdown with dedicated modify, revoke and add sections and a management sign-off block for the audit trail.
See it in the demoRequires only list and get permissions, runs on short-lived credentials, and never writes them to outputs, logs or reports.
See it in the demoBusiness Outcomes
Actionable
A triaged worklist with an action verdict per finding, rather than a spreadsheet that gets signed and filed without anything changing.
Defensible
A published scoring formula and a cited requirement per finding, so the review survives contact with an assessor.
Complete
Every account, every identity, every trust policy, with the run failing closed rather than quietly reviewing one account and calling it done.
Connect a read-only role and the first review returns a triaged worklist in minutes.