Platform

Machine identity management, from collection to cleanup

One read only connection per cloud account produces a continuously maintained inventory of nonhuman identities, the context to judge them, and the actions to fix them.

Continuous discovery

Read only roles enumerate IAM users and roles, service accounts, access keys, API tokens, certificates, workload identities, and AI agent credentials. Collection reruns on a schedule, so the inventory reflects the cloud as it is now, not as it was during the last audit.

Attribution

Every identity carries an owner, the workload it serves, and its last observed activity. Identities with no owner or no activity are flagged as orphan candidates instead of being lost in a flat export.

Scoring and drift

Blast radius is calculated from reachable resources and effective privilege, then rescored as permissions and exposure change. New, escalated, and newly dormant credentials appear as changes rather than as a fresh full list.

Remediation and workflow

Credential rotation, privilege reduction, and orphan cleanup run from the findings view. Findings can flow into ConnectWise and Kaseya so the work lands in the ticket queue that already exists.

Coverage

AWS, Azure, and GCP: same model, same inventory

Identity types differ per cloud; the inventory does not. Findings, attribution, and scoring use one schema across providers.

Amazon Web Services logo

AWS

  • IAM users & roles
  • Access keys
  • STS assumed roles
Microsoft Azure logo

Azure

  • Service principals
  • Managed identities
  • App secrets
Google Cloud Platform logo

GCP

  • Service accounts
  • Key files
  • Workload identity
Astrolayb

AI-powered IAM scanning

Astrolayb reads IAM policies across AWS, Azure, and GCP, flags identity vulnerabilities and misconfigurations, and returns step-by-step remediation guidance. It will converge with the Avistar platform so findings feed directly into the machine identity inventory.

Architecture

Secure by design

Collection uses least privilege read roles you grant and can revoke. Nothing is installed inside your workloads, and remediation actions are explicit and recorded.

  • No agents, sidecars, or in-workload software.
  • Least privilege read roles, revocable at any time.
  • Metadata about identities and permissions, not your application data.
  • Every remediation action is attributable and logged.

See every machine identity in your cloud

Book a walkthrough, or start with a single client gap assessment: agentless, read only, no commitment.