Your team ships a new IAM role for a Lambda function.
Someone attaches AdministratorAccess because it's Friday. Two years later it's still there — the Lambda has been retired, but the role still exists, still trusts every principal, and still has full write access to production. Multiply that by every service, every team, every environment. That is your real identity attack surface.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Onam ingests every IAM object across your clouds — users, roles, groups, service accounts, policies, and trust relationships — via read-only APIs.
- 2
The engine resolves effective permissions per identity, walking every policy, group membership, and cross-account trust to compute what an identity can actually do.
- 3
Recent activity from CloudTrail, Azure Activity Log, and GCP Cloud Audit Logs is joined against granted permissions to expose the unused surface.
- 4
The result is a per-identity least-privilege gap score, plus prioritised recommendations that generate a right-sized policy from real 90-day usage.
- 5
Findings refresh continuously so new identities, new grants, and new activity are reflected within minutes — no manual re-scan.
Specific outputs, measurable outcomes
CIEM in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see CIEM in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.