Skip to content
Cyber Defence

Least-Privilege Access Clean-Up

Each cloud identity compared against the permissions it has really used, with over-generous roles reduced carefully so nothing in production breaks.

10 working days₹20,999 incl. GST7 deliverables
Overview

What this service covers

Access tends to grow unchecked: temporary production rights never removed, an automation role given full admin because writing a proper policy seemed tedious. Using access analysis and audit logs, we compare each identity's granted rights with its real activity over 90 days, then draft least-privilege policies to replace broad ones. Nothing is tightened blindly; every change is proposed, reviewed with you and applied only where safe, in agreed batches. We also flag dormant identities and unused keys, review multi-factor authentication and root settings, check cross-account trust, and document a quarterly access review for your team.

Deliverables

What you receive

  • A full list of users, roles, service identities and access keys
  • Granted permissions compared with 90 days of recorded activity
  • Least-privilege policies written and ready to apply
  • Dormant identities and unused keys listed, with a removal plan
  • A check of root account settings and multi-factor authentication
  • A review of cross-account trust and external access
  • A documented quarterly access review routine for your team
How it runs

The work in 4 stages

  1. Stage 1: Gather

    Identity lists and activity logs are pulled together and analysed.

  2. Stage 2: Measure

    Each identity's permissions are compared with its actual use.

  3. Stage 3: Recommend

    Narrower policies are drafted, then reviewed alongside the teams responsible.

  4. Stage 4: Roll out

    Changes go live batch by batch as agreed, with rollback prepared.

Fit and inputs

Who it suits, and what we need from you

Ideal for

  • Cloud accounts where permissions have built up unchecked for years
  • Businesses where former staff might still have access
  • Teams facing an audit where least privilege will come up

What we need from you

  • Read-only access for auditing each cloud account in scope
  • Confirmation of who owns each service identity
  • A change window for applying the agreed policies

You share these through the brief on your order page after checkout.

Why it helps

What changes for your team

  • A leaked key grants far less access than it would now
  • Unused credentials and former staff access are found and removed
  • A quarterly review your team can run on its own
Questions

Questions about this service

This is why changes rest on 90 days of recorded activity and are applied in batches. Anything unclear is flagged, not guessed.

Yes, using each provider's equivalent identity services. Let us know your provider when you order.

Only with your written sign-off for each batch. Nothing is removed without approval.

This is a remote service: nothing is shipped physically, and the work is delivered into systems you control. See delivery and handover and refunds and cancellation for the full terms.

Related services

Often considered alongside this one

All Cyber Defence