Unused permissions, stale keys and leftover access found and removed.
Access piles up. People change teams, contractors leave, service roles keep permissions nobody uses. Agents read IAM, your identity provider and CloudTrail every day, find the access nobody needs, and remove it with an owner’s approval. Every grant and every removal lands in one audit trail.
Role data-export-legacy in account prod-analytics
Waiting for the data platform lead to approve
[The work behind every access review]
01The manual work
Review
Twice a year, someone exports IAM and Okta, sends spreadsheets to managers and chases answers for weeks.
02The agent handoff
Cleanup ready
Frontier agents check usage every day, match each grant to an owner and prepare the removal for review.
03Your team’s role
Approve
Set the rules for what counts as unused. Owners approve each removal, and anything sensitive waits for security.
[Where CloudThinker fits]
01Access sources
Already in your clouds
No change to your directory
02Identity and secrets
Your system of record
Source of truth stays put
03Governance
CloudThinker
Read-only by default
04Response
Less access, on record
Revocation runs on approval
[Example scenario]
A 120-person fintech on AWS Organizations with 18 accounts, Okta and GitHub. A contractor rolls off today, and the SOC 2 audit window opens Monday.
Offboarding ticket opensSignal
HR closes the contract in the HR system. ServiceNow opens OFF-2291 for the platform team.
Agent maps every grantAgent
Finds the Okta account, 3 IAM Identity Center permission sets, 1 IAM user with an access key, GitHub org membership and a Vault token.
Finds the one nobody listedAgent
The IAM user in account payments-staging has an access key used 2 hours ago from a CI runner. Removing it blindly would break a pipeline.
Plan posted for approvalAgent
Revoke Okta, permission sets, GitHub and Vault now. Rotate the CI key to a role first, then delete the user.
Security lead approvesYour team
Approves the plan in Slack and assigns the CI change to the pipeline owner.
Done and recordedAgent
All access removed, the pipeline moved to a role, and the evidence attached to OFF-2291 for the auditors.
ServiceNow16:40
OFF-2291 opened: offboard contractor, platform team, effective today 18:00.
CloudThinker16:45
Found 7 grants across Okta, IAM Identity Center, IAM, GitHub and Vault. One IAM access key is still used by ci-runner-04 in payments-staging. Plan: revoke 6 now, move the pipeline to a role, then delete the key.
Security lead16:52
Approved. Pipeline owner, please confirm the role swap.
CloudThinker17:06
All 7 grants removed. ci-runner-04 now uses role ci-payments-staging, builds green. Evidence attached to OFF-2291.
An illustrative example. Team, systems and times are representative, not a specific customer.
[Frontier governance agents]
Agents watch access the way your auditors wish you did: every day, across every account, with removals that wait for an owner before anything changes.
[What changes]
| Moment | Today | With frontier agents |
|---|---|---|
| Access reviews | Twice a year, by spreadsheet | Every day, with owners attached |
| Offboarding | A checklist that misses one system | Every grant found and closed on the last day |
| Stale keys | Found by the auditor | Flagged with the workload that still uses them |
| Permission cleanup | Too risky to touch | Reviewed pull requests with usage evidence |
| Audit evidence | Screenshots in a shared folder | Every grant and removal recorded as it happens |
[Integrations]
[Adoption path]
The rollout follows the four phases of the AWS Cloud Adoption Framework, so it fits the plan your cloud team already runs.
01Envision
Start with one account
Connect one AWS account and your identity provider read-only. Agents report unused access without changing anything.
02Align
Agree what unused means
Set the usage windows, the owners and which access always needs security sign-off.
03Launch
Roll out across the org
Add every account and tie offboarding tickets to the same checks and audit trail.
04Scale
Make it the default
New roles get an owner and an expiry at creation. Access reviews become a report, not a project.
[AWS guidance]
[Trust and control]
[Questions]
[Go deeper]
Start with one account, read-only. See the unused access agents find before you approve a single change.

Up to $200K in AWS credits
Applied to your own AWS account.

AWS AI Services Competency
Validated for Agentic AI Consulting.

Covered 24/7, on your approval
Under HIPAA, GDPR and SOC 2 controls.