Machine identity management, from collection to cleanup
One read only connection per cloud account produces a continuously maintained inventory of nonhuman identities, the context to judge them, and the actions to fix them.
Continuous discovery
Read only roles enumerate IAM users and roles, service accounts, access keys, API tokens, certificates, workload identities, and AI agent credentials. Collection reruns on a schedule, so the inventory reflects the cloud as it is now, not as it was during the last audit.
Attribution
Every identity carries an owner, the workload it serves, and its last observed activity. Identities with no owner or no activity are flagged as orphan candidates instead of being lost in a flat export.
Scoring and drift
Blast radius is calculated from reachable resources and effective privilege, then rescored as permissions and exposure change. New, escalated, and newly dormant credentials appear as changes rather than as a fresh full list.
Remediation and workflow
Credential rotation, privilege reduction, and orphan cleanup run from the findings view. Findings can flow into ConnectWise and Kaseya so the work lands in the ticket queue that already exists.
AWS, Azure, and GCP: same model, same inventory
Identity types differ per cloud; the inventory does not. Findings, attribution, and scoring use one schema across providers.
AWS
- IAM users & roles
- Access keys
- STS assumed roles
Azure
- Service principals
- Managed identities
- App secrets
GCP
- Service accounts
- Key files
- Workload identity
AI-powered IAM scanning
Astrolayb reads IAM policies across AWS, Azure, and GCP, flags identity vulnerabilities and misconfigurations, and returns step-by-step remediation guidance. It will converge with the Avistar platform so findings feed directly into the machine identity inventory.
Secure by design
Collection uses least privilege read roles you grant and can revoke. Nothing is installed inside your workloads, and remediation actions are explicit and recorded.
- No agents, sidecars, or in-workload software.
- Least privilege read roles, revocable at any time.
- Metadata about identities and permissions, not your application data.
- Every remediation action is attributable and logged.
See every machine identity in your cloud
Book a walkthrough, or start with a single client gap assessment: agentless, read only, no commitment.