CIEM

Who can access what — and should they still have that access?

80% of cloud permissions are never used. Every unused permission is a door that doesn't need to exist.

Identity is the new perimeter. CIEM resolves the effective permissions of every human user, service account, and machine identity across all your clouds — then compares them against what was actually used in the last 90 days. The gap is your attack surface.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

Your team ships a new IAM role for a Lambda function.

Someone attaches AdministratorAccess because it's Friday. Two years later it's still there — the Lambda has been retired, but the role still exists, still trusts every principal, and still has full write access to production. Multiply that by every service, every team, every environment. That is your real identity attack surface.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Onam ingests every IAM object across your clouds — users, roles, groups, service accounts, policies, and trust relationships — via read-only APIs.

  2. 2

    The engine resolves effective permissions per identity, walking every policy, group membership, and cross-account trust to compute what an identity can actually do.

  3. 3

    Recent activity from CloudTrail, Azure Activity Log, and GCP Cloud Audit Logs is joined against granted permissions to expose the unused surface.

  4. 4

    The result is a per-identity least-privilege gap score, plus prioritised recommendations that generate a right-sized policy from real 90-day usage.

  5. 5

    Findings refresh continuously so new identities, new grants, and new activity are reflected within minutes — no manual re-scan.

What do you actually get?

Specific outputs, measurable outcomes

Effective permissions resolved for every identity
not just what's attached
Least-privilege gap score (0–100) for each user, role, and service account
Shadow admin detection
identities that reach admin without an admin role
Stale identity list
accounts and keys unused for 90+ days
Cross-account trust chain analysis
external access you may not know about
Suggested least-privilege policies based on 90-day actual usage
MFA coverage report for privileged identities
Attack path visualisation
how a low-privilege identity reaches admin
See it live

CIEM in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

IAM Security
Run IAM Scan
189
Total Identities
47
Overprivileged
3
No MFA (Admin)
8
Wildcard Policies
Loading live data…
Find the identities that can hurt you
189 identities → 47 overprivileged, 3 admins without MFA, 8 wildcard policies
Clip length
10s
Data
Demo account
FAQ

Questions we get a lot

For usage-based recommendations, yes — CloudTrail (AWS), Activity Log (Azure), or Cloud Audit Logs (GCP) provide the 90-day baseline. Static findings like shadow admin, cross-account trust, and MFA gaps do not require logs and work immediately on connection.
Ready to see it live

Ready to see CIEM in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.