Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Strong answers give a per-cloud, per-identity-type breakdown; a tool that's deep on AWS but shallow on Azure/GCP should say so rather than imply uniform coverage.
Look for granular, action-level usage analysis (not just 'this role was used') and a concrete before/after reduction figure tied to a named customer.
Automated least-privilege policy generation with a low-friction apply path is materially stronger than a report listing excessive permissions the customer must manually rewrite into policy language.
Attack-path modeling (graph-based, showing how permissions chain into privilege escalation) is stronger than a static list of individually-risky permissions with no path analysis.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Look for a real JIT workflow with a stated production approval-latency figure, not a theoretical capability; JIT is the practical alternative to broad standing entitlements this category should offer.
Non-human identities are usually the majority of entitlements in a cloud account; a platform that treats them as an afterthought misses most of the actual attack surface.
PR-based remediation matching the customer's existing infrastructure-as-code workflow is stronger than a tool that only makes live, out-of-band changes bypassing change management.
Built-in certification workflow with tracked sign-off is stronger than a raw entitlement export requiring the compliance team to build their own review process around it.
Same tension as other discovery-driven categories: successful entitlement discovery inherently increases the counted identity population, especially given non-human identities typically outnumber human ones — ask explicitly how pricing handles a large post-onboarding jump.
Strong answers describe a fast, specific blast-radius assessment capability with a real customer example, not just preventive posture monitoring.
Trend-over-time reporting is a distinct capability from a real-time posture dashboard — confirm this exists as a maintained, exportable report.
Look for genuine integration into a unified identity risk view; a standalone CIEM dashboard disconnected from the broader PAM/IAM picture creates real reconciliation burden.
A complete attack-path map is a meaningful target in its own right — role-based access control over the tool's own findings is an often-overlooked consideration.
A high false-positive rate on attack-path flagging creates real alert fatigue — ask for a real, customer-validated accuracy figure and a correction workflow that accounts for compensating controls.
Genuine multi-entity isolation is materially more useful for a diversified organization than one shared view forcing a one-size-fits-all entitlement posture.
Strong answers give a concrete, customer-validated timeline for a realistic existing-sprawl scenario (not a small greenfield deployment), and are honest about the customer-side effort required.