Onam Security

Right-sizing workflow

Right-sizing turns a CIEM finding into a smaller grant: pick who to review, see what they use, decide, change it, then check the next scan.

From identity risk score to access review
From identity risk score to access review

1. Find who to review

On AWS, every role and user gets a 0–100 risk score. The parts:

PartPoints
Escalation paths10 per path, up to 30
Recent escalation activity seen by CDR40
Blast radius2 per reachable resource with an open high or critical finding, up to 20
Permission gapgap percentage ÷ 5, up to 20

Tiers: critical 80 and above, high 60 and above, medium 30 and above, otherwise low. Identities in the high tier or above open an access review automatically, with the highest-scoring first.

2. See what it uses (AWS)

The permission gap compares the actions an identity has been granted with the actions CloudTrail shows it calling in the recent activity window. The review row shows:

  • Least privilege — the share of granted actions not called;
  • Granted and Used — the counts behind it;
  • High-risk unused — unused grants that matter most, such as iam:PassRole, iam:CreatePolicyVersion, iam:AttachRolePolicy, s3:DeleteBucket, s3:PutBucketPolicy, kms:ScheduleKeyDeletion, sts:AssumeRole.

Usage comes from CloudTrail events collected by Onam's threat detection. With no CloudTrail flowing, every grant looks unused — check that first.

3. Decide

In CIEM → Access Reviews, a reviewer with the review:decide permission marks each identity:

StateMeaning
PendingWaiting for a decision
Needs remediationSomething must change
ReviewedDecision recorded, no change needed
DeferredPostponed, and the postponement recorded

Every change is written to an audit trail with the reviewer and time. Decisions expire after a set period and return to pending, and if a reviewed or deferred identity is flagged again it goes back to pending.

4. Change it

Onam does not edit your IAM. Remove the high-risk unused actions first — they cut the most risk per change — in your own console or infrastructure-as-code. Before removing anything, allow for jobs that run less often than the activity window, such as quarter-end batch jobs and disaster-recovery roles.

A suggested least-privilege policy is in development. Until it ships, build the replacement from the Used actions.

5. Check the next scan

On the next scan the gap, escalation and score are recomputed. A closed escalation path drops its points and the finding resolves; a reduced grant lowers the gap.

Over the API

The access-review workflow is available on the platform API:

GET  /api/v1/iam-security/access-review              # list reviews (filter by status)
POST /api/v1/iam-security/access-review/{identity}    # record a decision: reviewed | needs_remediation | deferred

The decision endpoint requires the review:decide permission. See the API reference for authentication.