The vaultIAM Way
You see every query before you grant us any access.
Every engagement starts with a read-only look at the tools you already pay for, using a query list we publish in advance, and ends with your team running it without us. Nothing we do requires you to buy anything or keep us on.
The Identity Risk Assessment
What the assessment actually looks at.
- Read-only queries through each platform's own admin API — Microsoft Graph, the Okta API, AWS IAM and Access Analyzer, Azure and GCP IAM, CyberArk, Active Directory, GitHub, Kubernetes RBAC* — plus our own scripts, all of which we show you
- The permission set we need is published before we ask for it, and the check list is the same one every time — no discretionary access, no surprises
- Checks across permanent admin access, credential hygiene, the routes an attacker could take between accounts, machine identity ownership, and conditional-access policy gaps
- Every finding mapped to FFIEC/NYDFS, HIPAA Section 164.312, SOC 2 CC6, OSFI B-13 and PIPEDA/Law 25 — with honest coverage disclosure per framework, because no automated check covers a whole framework
- Runs inside your environment; nothing is uploaded to us or any third party
Identity Risk Assessment — sample layout
61
of 100
14 standing privileged accounts without JIT
Entra ID · Privileged roles
31 service accounts with no accountable owner
AWS IAM · NHI inventory
Conditional Access gap: legacy auth unblocked
Entra ID · CA policies
9 API keys older than 365 days
Cloud IAM · Credential hygiene
Framework coverage (automated controls)
FFIEC / NYDFS
HIPAA Section 164.312
SOC 2 CC6
PIPEDA / Law 25
How the work runs
Three phases. Take only the ones you need.
- 01 2 weeks
Assess
We run read-only queries against the systems you already have — Entra ID, Okta, AWS/Azure/GCP IAM, CyberArk, AD, GitHub, Kubernetes — using each platform's own admin APIs plus our scripts. Zero agents, zero config changes, nothing leaves your network.
You get
Scored, board-ready report
Fixed scope, fixed fee
- 02 6–8 weeks
Harden
Sprints close the highest-risk gaps using tools you already license. Every change documented, every decision transferable, every step handed over.
You get
Hardened controls + runbooks
Scope fixed per sprint
- 03 Quarterly
Assure
Optional quarterly re-checks catch drift before examiners do. Cancel anytime — never contractually required, never a condition of the work above.
You get
Drift & compliance delta report
Optional · cancel anytime
* Platform and product names identify systems we work with. They do not imply partnership, certification, or endorsement by their owners.
See these queries run against your own systems
The assessment described above, on your systems, with the query list shown to you first. Thirty minutes to scope it, a fixed fee, and the findings are yours whatever you decide to do next.
Book an Identity Risk Review