Console’s review
· Reviewed by David Mytton
What we like
Control access to cloud resources (AWS, GCP, k8s, Postgres, Snowflake) with just in time approvals. Approved entitlements must have an expiry - great to avoid long-lived credentials. Route requests to the right approvers, configured in code. PagerDuty integration for auto-approving when on-call. IAM Audit feature highlights overly permissive policies.
Tradeoffs
IAM Audit currently only works with GCP (main approval flows work across multiple cloud resources).