Core job 02 / IAM clarity

Permissions,
without the
puzzle.

Somebody on your team wrote that policy two years ago. CloudValet reads all of them, tells you in plain words what they allow, and shouts when they change.

Three jobs on
one map of access.

Access review shouldn't be an annual spreadsheet exercise. We keep it live, readable, and noisy only when it matters.

01

Monitor

A live picture of access

We read every role, group, policy, and key across your accounts and keep an up-to-date map of effective access: what each identity can really do once inheritance and conditions are resolved.

  • Users, roles, service accounts and keys
  • Effective permissions after inheritance and conditions
  • Cross-account and cross-provider view
02

Audit

Plain English, not policy JSON

Each policy becomes a sentence anyone in the business can read: "this role can delete any storage bucket in production." Then we grade it against what the identity actually used.

  • One-line translation per statement
  • Unused permissions after 30 / 60 / 90 days
  • Over-permissioned and dormant accounts
03

Alert

Told the moment it drifts

Permissions widen quietly. We watch for new grants, removed guardrails, fresh keys, and privilege escalation paths, then tell the right person with the change spelled out.

  • New, removed and widened access
  • Escalation paths and admin sprawl
  • Slack, Teams, email and webhook delivery

Same policy. Now in a language your whole team reads.

"Action": "s3:*", "Resource": "*"

Can read, change and permanently delete every file in every storage bucket, including production backups.

Too broad
"Action": "iam:PassRole", "Resource": "*"

Can hand any role to a service, a path to becoming an administrator without being one.

Escalation path
"Action": ["ec2:StartInstances","ec2:StopInstances"]

Can start and stop virtual machines in the dev account. Cannot create, resize or delete them.

Right-sized

Illustrative examples of the translations CloudValet produces.

Answers, not another dashboard to interpret.

Who can do what

Search by person, team, role, or resource and get a direct answer instead of a policy tree to interpret.

Readable policy summaries

Every dense statement rendered as a sentence, with the risky ones surfaced first.

Unused access

Identities and permissions nobody has touched in months, ranked by the damage they could do.

Least privilege suggestions

A narrower policy proposed alongside the original, with the permissions the identity actually used.

Change history

A timeline of every access change with who made it, when, and what it opened up.

Routed alerts

Route production alerts to security and sandbox noise to the owning team, so alerts stay worth reading.

Read-only by default. CloudValet needs no permission to change your permissions.

IAM monitoring runs on scoped read access. Any change to access stays in your hands. We show the narrower policy, you decide whether to apply it.

Clarity on
every plan.

Plain-English policy summaries are free forever. Continuous monitoring, unused-access reports and change alerts come with Pro; approvals and audit history with Enterprise.

Free

$0

forever, up to 25 resources

Connect one cloud account read-only, see the waste, and read your IAM in plain English.

  • Idle and oversized resource discovery
  • Plain-English IAM policy summaries
  • Manual start / stop of parked resources
  • One connected cloud account
  • Weekly waste digest by email
Start free
Pro

$0.25

per managed resource / month

Automated parking schedules, rightsizing plans, and IAM change alerts for the whole team.

  • Unlimited parking schedules with calendar and holiday rules
  • Auto start before work, auto stop after hours
  • Rightsizing recommendations with projected savings
  • IAM change, unused-access and over-permission alerts
  • Slack, Teams and webhook notifications
  • Savings and access reporting for finance
  • Unlimited accounts across AWS, Azure and Google Cloud
Book a demo
Enterprise

Custom

annual, volume-based

For large estates, managed providers, and teams with audit and approval requirements.

  • SSO and role-based access with delegated teams
  • Approval workflows for parking and access changes
  • Least-privilege recommendations with audit history
  • Multi-tenant views for managed service providers
  • API access and custom policy guardrails
  • Named engineer and onboarding support
Talk to us

Pre-launch pricing. Nothing is charged today. Design partners help us set the final numbers, and checkout opens at launch.

Curious what your IAM actually allows?

Book an IAM walkthrough