Frontier Governancefor Cloud Access

Unused permissions, stale keys and leftover access found and removed.

Access piles up. People change teams, contractors leave, service roles keep permissions nobody uses. Agents read IAM, your identity provider and CloudTrail every day, find the access nobody needs, and remove it with an owner’s approval. Every grant and every removal lands in one audit trail.

Daily access reviewunused access

Role data-export-legacy in account prod-analytics

Principal
IAM role used by a retired nightly export job
Granted
s3:* and kms:Decrypt on 14 buckets, including customer-pii
Last used
143 days ago, per CloudTrail and IAM last accessed data
Owner
Data platform team, from the Terraform module
Fix
Detach policies now, delete the role in 30 days. Reversible

Waiting for the data platform lead to approve

[The work behind every access review]

Access is granted in minutes.It is removed once a year, if at all.

01The manual work

Review

Twice a year, someone exports IAM and Okta, sends spreadsheets to managers and chases answers for weeks.

02The agent handoff

Cleanup ready

Frontier agents check usage every day, match each grant to an owner and prepare the removal for review.

03Your team’s role

Approve

Set the rules for what counts as unused. Owners approve each removal, and anything sensitive waits for security.

[Where CloudThinker fits]

Your stack stays.Agents work inside it.

01Access sources

Already in your clouds

  • AWSAWS IAMUsers, roles, keys and policies
  • AzureMicrosoft Entra IDUsers, groups and Azure RBAC
  • Google CloudGoogle Cloud IAMPrincipals, roles and service accounts
  • GitHubGitHub and GitLabOrg members, tokens and CI secrets
  • KubernetesKubernetes RBACCluster roles and bindings

No change to your directory

02Identity and secrets

Your system of record

  • OktaWho works here and on which team
  • VaultHashiCorp VaultSecrets and dynamic credentials
  • AWSAWS CloudTrailWhat each identity actually used
  • ServiceNowAccess requests and approvals

Source of truth stays put

03Governance

CloudThinkerCloudThinker

  • InventoryEvery human and machine identity
  • CompareGranted access against real use
  • ProveLast-used evidence for each grant
  • RemoveRevocations staged for approval

Read-only by default

04Response

Less access, on record

  • TerraformPolicy changes as a pull request
  • SlackSlackOwners confirm or keep access
  • JiraExceptions tracked with an expiry
  • Audit evidenceBefore and after for the auditor

Revocation runs on approval

Logos show common stacks. CloudThinker reads identities and usage through read-only access you approve.

[Example scenario]

Friday, 16:40. A contractor’s last day.Their access is still everywhere.

A 120-person fintech on AWS Organizations with 18 accounts, Okta and GitHub. A contractor rolls off today, and the SOC 2 audit window opens Monday.

  1. 16:40

    Offboarding ticket opensSignal

    HR closes the contract in the HR system. ServiceNow opens OFF-2291 for the platform team.

  2. 16:41

    Agent maps every grantAgent

    Finds the Okta account, 3 IAM Identity Center permission sets, 1 IAM user with an access key, GitHub org membership and a Vault token.

  3. 16:43

    Finds the one nobody listedAgent

    The IAM user in account payments-staging has an access key used 2 hours ago from a CI runner. Removing it blindly would break a pipeline.

  4. 16:45

    Plan posted for approvalAgent

    Revoke Okta, permission sets, GitHub and Vault now. Rotate the CI key to a role first, then delete the user.

  5. 16:52

    Security lead approvesYour team

    Approves the plan in Slack and assigns the CI change to the pipeline owner.

  6. 17:06

    Done and recordedAgent

    All access removed, the pipeline moved to a role, and the evidence attached to OFF-2291 for the auditors.

#access-reviews4 messages
  • ServiceNow16:40

    OFF-2291 opened: offboard contractor, platform team, effective today 18:00.

  • CloudThinker16:45

    Found 7 grants across Okta, IAM Identity Center, IAM, GitHub and Vault. One IAM access key is still used by ci-runner-04 in payments-staging. Plan: revoke 6 now, move the pipeline to a role, then delete the key.

  • Security lead16:52

    Approved. Pipeline owner, please confirm the role swap.

  • CloudThinker17:06

    All 7 grants removed. ci-runner-04 now uses role ci-payments-staging, builds green. Evidence attached to OFF-2291.

from ticket to fully offboarded
26 min
grants found, including one nobody listed
7
broken pipelines
0

An illustrative example. Team, systems and times are representative, not a specific customer.

[Frontier governance agents]

Every grant has an owner.Every unused one has an end date.

Agents watch access the way your auditors wish you did: every day, across every account, with removals that wait for an owner before anything changes.

Map every grant
IAM users, roles, permission sets, Okta groups and repo access joined into one view per person and per workload.
Find stale keys
Long-lived access keys and tokens flagged by age and last use, with the workload that still depends on them.
Close the leavers
Offboarding tickets checked against every system, so access ends on the last day and not at the next review.
Right-size permissions
Unused services and actions trimmed from policies, with the change prepared as a Terraform pull request.

[What changes]

Same team. Same tools.Far less of the work by hand.

MomentTodayWith frontier agents
Access reviewsTwice a year, by spreadsheetEvery day, with owners attached
OffboardingA checklist that misses one systemEvery grant found and closed on the last day
Stale keysFound by the auditorFlagged with the workload that still uses them
Permission cleanupToo risky to touchReviewed pull requests with usage evidence
Audit evidenceScreenshots in a shared folderEvery grant and removal recorded as it happens

[Integrations]

Connects to the rest of your stack.Read-only to start.

  • AWS IAM
  • AWS IAM Identity Center
  • IAM Access Analyzer
  • AWS CloudTrail
  • AWS Organizations
  • Okta
  • CyberArk
  • HashiCorp Vault
  • 1Password
  • GitHub
  • GitLab
  • Terraform
  • ServiceNow
  • Slack

[Adoption path]

One pilot.Then company-wide.

The rollout follows the four phases of the AWS Cloud Adoption Framework, so it fits the plan your cloud team already runs.

  1. 01Envision

    Start with one account

    Connect one AWS account and your identity provider read-only. Agents report unused access without changing anything.

  2. 02Align

    Agree what unused means

    Set the usage windows, the owners and which access always needs security sign-off.

  3. 03Launch

    Roll out across the org

    Add every account and tie offboarding tickets to the same checks and audit trail.

  4. 04Scale

    Make it the default

    New roles get an owner and an expiry at creation. Access reviews become a report, not a project.

[Trust and control]

Agents do the work.Your team keeps control.

You approve every change
Agents propose. Nothing touches production until someone on your team says yes, and you set that rule per system.
Every action on the record
Each step is logged, attributed and reversible, ready for your auditors.
Certified for enterprise
SOC 2 Type II and ISO 42001, with reports in our trust center.
Runs where you need it
In our cloud, through AWS Marketplace, or inside your own account.

[Questions]

What teams askbefore they start.

Will agents remove access on their own?
Only where your policy allows it. By default every removal waits for the owner, and sensitive access waits for security as well.
What if a pipeline still uses the key?
Agents check recent use before proposing a removal. If something still depends on the key, the plan moves that workload to a role first.
Does this replace IAM Access Analyzer?
No. Agents read its findings alongside CloudTrail, your identity provider and Terraform, then add the owner, the context and the fix.
What access do agents need?
Read-only to start. Write access is scoped to the changes you approve, issued per action and revocable at any time.

Know who can touch what.And remove what nobody needs.

Start with one account, read-only. See the unused access agents find before you approve a single change.

  • A CloudThinker team member holding a card reading "up to $200K active AWS credits"

    Up to $200K in AWS credits

    Applied to your own AWS account.

  • A CloudThinker team member presenting the AWS Partner AI Services Competency badge for Agentic AI Consulting Services

    AWS AI Services Competency

    Validated for Agentic AI Consulting.

  • An engineer approving a request beside a global operations map, an uptime dial, and HIPAA, GDPR and SOC compliance marks

    Covered 24/7, on your approval

    Under HIPAA, GDPR and SOC 2 controls.