CIEM · identities · least privilege

Most cloud access
is never used.

Human users, service accounts, roles and workload identities accumulate permissions and never lose them. OnDuty CIEM maps what every identity can actually do, what it actually uses, and shrinks the gap — safely, and without breaking production.

Identity risk, by the numbers

Permissions grow.
They never shrink.

Every identity — human, service account, role or workload — accumulates access over time and rarely loses it. OnDuty CIEM shows exactly what's unused, what's risky, and what's safe to revoke, backed by real usage data.

2%

Avg. permissions actually used

Across human & machine identities

5x

More non-human identities

Than human users, in most orgs

91%

Excess permissions removable

Without breaking workflows

15 min

Median onboarding

Read-only, agentless discovery

Six capabilities, one platform

CIEM, grounded in
real usage data.

Capability / 01

Full identity inventory

Discover every human user, service account, role and workload identity across AWS, Azure, GCP and OCI — agentless.

  • Human & non-human identities
  • Federated & SSO identities
  • Cross-cloud normalization
Capability / 02

Granted vs. used analysis

Compare every granted permission against actual usage logs to find the real gap between access and need.

  • Usage-based analysis
  • Unused permission scoring
  • Cross-account visibility
Capability / 03

Toxic permission combinations

Detect privilege escalation paths and toxic combinations — like assume-role chains that lead to admin — before attackers find them.

  • Escalation path graph
  • Cross-account trust risk
  • Shadow admin detection
Capability / 04

Least-privilege remediation

Generate right-sized policies automatically, with safe rollout and rollback — no more all-or-nothing access reviews.

  • Auto-generated policies
  • Safe rollout & rollback
  • Break-glass exceptions
Capability / 05

Just-in-time access

Grant elevated access only when needed, for a fixed window, with full audit trail — instead of standing privilege.

  • Time-bound elevation
  • Approval workflows
  • Full audit trail
Capability / 06

Continuous entitlement compliance

Map identity risk to CIS, SOC 2 and ISO controls, with evidence that access reviews actually happened.

  • Access review evidence
  • Framework mapping
  • Executive risk scorecards

The Identity Graph

One graph. Every identity.

Every permission is tied to the identity that holds it, the resources it touches and the escalation paths it enables — so you see the one path that leads to admin, not a wall of unused-permission tickets.

Explore the dashboard
Identity graph · org-root · all clouds LIVE
Identity
Permission
Resource
Escalation

Service account can assume-role to admin

sa:ci-deploy → role/org-admin · 3-hop escalation path

IAM user has unused AdministratorAccess

user:jsmith · 0 API calls in 90d · full admin policy

Cross-account trust overly permissive

role/prod-readonly · trusts *:root · 4 external accounts

Standing access unused for 60+ days

role/legacy-etl · last used 2024-09-01

The CIEM lifecycle

From standing access
to least privilege.

Phase / 01

Discover

Agentless discovery of every human and machine identity, role and permission across every cloud.

Phase / 02

Analyze

Compare granted permissions to actual usage and map escalation paths and toxic combinations.

Phase / 03

Right-size

Generate least-privilege policies automatically, with safe rollout and instant rollback.

Phase / 04

Govern

Enforce just-in-time access and prove continuous entitlement compliance with live evidence.

FAQ

Frequently asked questions.

CIEM (Cloud Infrastructure Entitlement Management) discovers every human and machine identity across your clouds, maps what each one is permitted to do, and compares that against what it actually uses. Instead of static access reviews, OnDuty continuously surfaces unused permissions, toxic combinations and escalation paths so you can shrink access to least privilege.

Shrink access to what's actually needed

See the path to admin,
not the 10,000 permissions.

See your real entitlement risk, unused permissions and escalation paths in a 30-min guided demo with our team.

  • Agentless inventory of every human & machine identity
  • Granted-vs-used analysis backed by real API usage logs
  • Escalation paths & toxic combinations mapped to admin
  • Auto-generated least-privilege policies with safe rollback
  • CIS · SOC 2 · ISO — access-review evidence, always current