Full identity inventory
Discover every human user, service account, role and workload identity across AWS, Azure, GCP and OCI — agentless.
- Human & non-human identities
- Federated & SSO identities
- Cross-cloud normalization
Human users, service accounts, roles and workload identities accumulate permissions and never lose them. OnDuty CIEM maps what every identity can actually do, what it actually uses, and shrinks the gap — safely, and without breaking production.
Identity risk, by the numbers
Every identity — human, service account, role or workload — accumulates access over time and rarely loses it. OnDuty CIEM shows exactly what's unused, what's risky, and what's safe to revoke, backed by real usage data.
2%
Avg. permissions actually used
Across human & machine identities
5x
More non-human identities
Than human users, in most orgs
91%
Excess permissions removable
Without breaking workflows
15 min
Median onboarding
Read-only, agentless discovery
Six capabilities, one platform
Discover every human user, service account, role and workload identity across AWS, Azure, GCP and OCI — agentless.
Compare every granted permission against actual usage logs to find the real gap between access and need.
Detect privilege escalation paths and toxic combinations — like assume-role chains that lead to admin — before attackers find them.
Generate right-sized policies automatically, with safe rollout and rollback — no more all-or-nothing access reviews.
Grant elevated access only when needed, for a fixed window, with full audit trail — instead of standing privilege.
Map identity risk to CIS, SOC 2 and ISO controls, with evidence that access reviews actually happened.
The Identity Graph
Every permission is tied to the identity that holds it, the resources it touches and the escalation paths it enables — so you see the one path that leads to admin, not a wall of unused-permission tickets.
Explore the dashboardService account can assume-role to admin
sa:ci-deploy → role/org-admin · 3-hop escalation path
IAM user has unused AdministratorAccess
user:jsmith · 0 API calls in 90d · full admin policy
Cross-account trust overly permissive
role/prod-readonly · trusts *:root · 4 external accounts
Standing access unused for 60+ days
role/legacy-etl · last used 2024-09-01
The CIEM lifecycle
Agentless discovery of every human and machine identity, role and permission across every cloud.
Compare granted permissions to actual usage and map escalation paths and toxic combinations.
Generate least-privilege policies automatically, with safe rollout and instant rollback.
Enforce just-in-time access and prove continuous entitlement compliance with live evidence.
FAQ
CIEM (Cloud Infrastructure Entitlement Management) discovers every human and machine identity across your clouds, maps what each one is permitted to do, and compares that against what it actually uses. Instead of static access reviews, OnDuty continuously surfaces unused permissions, toxic combinations and escalation paths so you can shrink access to least privilege.
Related solutions
OnDuty is one platform on a single graph. Here's where the rest of it connects.
Shrink access to what's actually needed
See your real entitlement risk, unused permissions and escalation paths in a 30-min guided demo with our team.