What It Does
How Sonrai Protects AWS
Sonrai continuously analyzes all 21k+ unique AWS permissions and monitors which identities – human, machine, and agent – actually use the ~1,300 sensitive ones. It then automatically generates organization-level Service Control Policies and Resource Control Policies that deny everything unused, with every active workflow exempted so nothing breaks.
Review the policies, deploy with one click in an IaC template, and your AWS org shifts from default allow to default deny.
Automated SCP creation & orchestration
Org-level deny policies built from real usage data, not guesswork. SCP compression keeps you under AWS size limits, and a control-capacity meter shows headroom against SCPs you’ve already deployed.
RCP automation
Resource Control Policies protect your S3, KMS, STS, Secrets Manager, and SQS resources from untrusted external access — generated and orchestrated alongside your SCPs.
Permissions on Demand
When someone needs a restricted permission, an automated ChatOps approval workflow identifies the blocking policy and updates it. No troubleshooting.
Just-in-time access
Time-limited grants that revoke themselves at expiry, enrolled at the organization, OU, or account level with one click. New permission sets enroll automatically. Admins can kill any active session instantly, and every session is logged with an activity summary.
Coverage for machine and agent identities
Your IAM roles, Lambda execution roles, EC2 instance profiles, and CI/CD pipelines vastly outnumber your humans and can’t log into a portal to request access. With Sonrai, the access attempt itself opens the request and routes it to the owner we discovered from your cloud — no SDK, no integration, no code change.
Continuous enforcement
New accounts, roles, and identities inherit the guardrails at the moment of creation.
Why it sticks
Why You Can Deploy It Without Fear
Every team we talk to already knows SCPs are the right answer. What stops them is the fear of the 2 a.m. page — of being the person who broke the deployment pipeline. Here’s the mechanism, not the reassurance:
We restrict ~2,500 permissions, not 47,000.
Only sensitive permissions are in scope, and only after 90+ days of non-use. The other ~44,500 are left alone, so a developer doing normal work never reaches the boundary.
The SCP is written from your usage data.
Anything currently using a permission is exempted automatically before the policy is generated. The deny only covers what nothing in your org is exercising.
You review the exemption list before anything deploys.
Connecting is effectively monitor mode — every identity using sensitive permissions is visible and editable. Nothing enforces until you click deploy.
Start in one account or OU.
Roll it out in limited scope or go org-wide – everything is scoped down to the account level, so it’s up to you how you start.
Getting access back takes seconds.
Requests and approvals run through Slack or Teams. The developer never learns what an SCP is, and nobody troubleshoots which policy caused a block.
Everything is reversible and logged.
Kill an active session instantly from the console; produce a full audit trail on demand.
“The challenge with deleting unused identities or enforcing least privilege is that we know it’s the ‘right’ thing to do, but everyone’s afraid it’ll break something or interrupt our development cycles. We don’t have to worry anymore.”
What You Get
Default Deny in Days, Not Months
The shortest time from discovery to control implementation
Usage analysis is finished in less than 24 hours. You can get your first controls live in a day. Everything is native to AWS IAM, nothing to new install. Want to start small? Toggle your scope between Org, OU, and Account levels and start wherever you want.
97% less time writing policies.
Stop hand-authoring SCPs and reconciling allow/deny conflicts across IAM, resource, and org policies.
92% reduction in attack surface.
More than 90% of identities never use the sensitive permissions they hold – remove them all at once. RCPs remove any unwanted third party access.
Nothing breaks.
The deny is generated from what your org actually uses, so it never covers a permission in use — and you review the exemption list before deploying.
What It Looks Like
How Fast is it
6 Months of Work, in 6 Days
Global Atlantic cut the time to fix identity and permissions problems from 6 months to 6 days.
“Within five minutes I had disabled regions that were unused across my entire AWS organization.”
“Sonrai helped us do in days what would’ve taken months — automating identity management and achieving least privilege across AWS.”
Why Use It
SCP & RCP Automation at Scale
Your team already knows SCPs and RCPs are the right guardrails. The problem is writing, testing, and maintaining them across dozens of accounts. Character limits, policy conflicts, exemption tracking, and the fear of blocking production make manual orchestration unscalable.
The Cloud Permissions Firewall does the analysis, writes the policies, manages the exemptions, and keeps them current as your org changes. And because we automate the guardrail mechanism AWS already gave you, there’s nothing new in the request path. No proxies, brokers, or bastion hosts to deploy or maintain. All the benefits of native controls, no burden of esoteric IAM knowledge, endless Access Analyzer runs, or time-consuming policy reviews.


