Right-sizing workflow
Right-sizing turns a CIEM finding into a smaller grant: pick who to review, see what they use, decide, change it, then check the next scan.
1. Find who to review
On AWS, every role and user gets a 0–100 risk score. The parts:
| Part | Points |
|---|---|
| Escalation paths | 10 per path, up to 30 |
| Recent escalation activity seen by CDR | 40 |
| Blast radius | 2 per reachable resource with an open high or critical finding, up to 20 |
| Permission gap | gap percentage ÷ 5, up to 20 |
Tiers: critical 80 and above, high 60 and above, medium 30 and above, otherwise low. Identities in the high tier or above open an access review automatically, with the highest-scoring first.
2. See what it uses (AWS)
The permission gap compares the actions an identity has been granted with the actions CloudTrail shows it calling in the recent activity window. The review row shows:
- Least privilege — the share of granted actions not called;
- Granted and Used — the counts behind it;
- High-risk unused — unused grants that matter most, such as
iam:PassRole,iam:CreatePolicyVersion,iam:AttachRolePolicy,s3:DeleteBucket,s3:PutBucketPolicy,kms:ScheduleKeyDeletion,sts:AssumeRole.
Usage comes from CloudTrail events collected by Onam's threat detection. With no CloudTrail flowing, every grant looks unused — check that first.
3. Decide
In CIEM → Access Reviews, a reviewer with the review:decide permission marks each identity:
| State | Meaning |
|---|---|
| Pending | Waiting for a decision |
| Needs remediation | Something must change |
| Reviewed | Decision recorded, no change needed |
| Deferred | Postponed, and the postponement recorded |
Every change is written to an audit trail with the reviewer and time. Decisions expire after a set period and return to pending, and if a reviewed or deferred identity is flagged again it goes back to pending.
4. Change it
Onam does not edit your IAM. Remove the high-risk unused actions first — they cut the most risk per change — in your own console or infrastructure-as-code. Before removing anything, allow for jobs that run less often than the activity window, such as quarter-end batch jobs and disaster-recovery roles.
A suggested least-privilege policy is in development. Until it ships, build the replacement from the Used actions.
5. Check the next scan
On the next scan the gap, escalation and score are recomputed. A closed escalation path drops its points and the finding resolves; a reduced grant lowers the gap.
Over the API
The access-review workflow is available on the platform API:
GET /api/v1/iam-security/access-review # list reviews (filter by status)
POST /api/v1/iam-security/access-review/{identity} # record a decision: reviewed | needs_remediation | deferredThe decision endpoint requires the review:decide permission. See the API reference for authentication.