Skip to content

Every engagement lists its scope, timeline and fixed fee before checkout

Techluminate

Cloud IAM Permissions Audit

Every identity in your cloud account reviewed against its actual usage, with over-permissioned roles tightened safely.

Timeline
10 working days
Deliverables
7 listed
Practice
Security & Compliance
Fixed fee
₹18,999
01Overview

What this engagement delivers

Permissions accumulate over time, from temporary production access that was never removed to a CI role given administrator rights because the correct policy was hard to define. We use access analyser and CloudTrail data to compare each identity's granted permissions with what it has actually used over 90 days, then write least-privilege policies to replace the broad ones. Nothing is tightened blindly: every change is proposed, reviewed with you and applied only where it will not break a working system.

02Deliverables 7 items

What you receive

  1. Inventory of every user, role, service account and access key
  2. Used-versus-granted comparison over 90 days of activity data
  3. Least-privilege policy recommendations written and ready to apply
  4. Unused credential and stale identity list with a removal plan
  5. Multi-factor authentication and root account configuration review
  6. Cross-account trust and external access review
  7. Quarterly access review process documented for your team
03Process

How the work runs, in 4 stages

  1. Stage 1: Collect

    Identity inventory and activity logs are gathered and analysed

  2. Stage 2: Compare

    Granted permissions measured against real usage per identity

  3. Stage 3: Propose

    Tightened policies drafted and reviewed with the owning teams

  4. Stage 4: Apply

    Changes rolled out in agreed batches with rollback ready

04Fit & inputs

Who it suits, and what we need from you

Ideal for

  • Cloud accounts where permissions have grown for years without review
  • Companies where former staff may still have valid access
  • Teams preparing for an audit that asks about least privilege

What we need from you

  • Read-only security audit access to the cloud accounts in scope
  • Confirmation of who currently owns each service account
  • A change window for applying the agreed policy updates

You provide these through the technical brief in your dashboard after checkout.

05Benefits

What changes for your team

  • 01

    A compromised key gives an attacker far less access than it would today

  • 02

    Departed staff and dormant credentials are found and removed

  • 03

    A repeatable quarterly review your team can run independently

06FAQ

Questions about this engagement

That is why we use 90 days of real usage data and roll out in batches. Anything ambiguous is flagged rather than guessed at.

Yes, with the equivalent identity services. Mention your provider at checkout.

Only with your written approval, batch by batch. Nothing is revoked unilaterally.

This is a remote engineering engagement — nothing is shipped physically. Work is delivered into systems you control. See delivery & handover and refunds & cancellation for the full terms.

Related engagements

Often considered alongside this one.

All Security & Compliance
Security & Compliance Popular

Web Application VAPT

A manual penetration test of your web application, with proof-of-concept evidence for each finding and a retest after remediation.

Manual penetration test covering authentication, authorisation and business logic

12 working days Scope published

Fixed fee · GST incl.

₹29,999

Security & Compliance TL-SEC-103

SOC 2 Evidence Groundwork

The technical controls and automated evidence collection a SOC 2 Type II audit requires, in place before the observation window begins.

Control gap assessment against the Trust Services Criteria you are scoping

30 working days Scope published

Fixed fee · GST incl.

₹44,999

Security & Compliance TL-SEC-105

Secrets and Dependency Hygiene Sprint

Credentials committed to your repositories found and rotated, with automated scanning set up to stop new ones slipping in.

Full git history secret scan across up to 20 repositories

6 working days Scope published

Fixed fee · GST incl.

₹12,999

Security & Compliance TL-SEC-102

DPDP Act Readiness Review

A practical gap assessment against India’s DPDP Act 2023, covering consent, retention, notices and breach procedures.

Personal data inventory across systems, vendors and storage locations

15 working days Scope published

Fixed fee · GST incl.

₹22,999

Next step

Bring the problem. Leave with a defined plan.

Pick the engagement that matches what you need, or tell us about the system you are working on and we will point you to the right starting place.