Live · Free 14-day trial, no card required

Standing AWS access is over. Get it just-in-time.

CloudGrant gives your developers time-boxed, approved, auto-expiring access to AWS - roles, accounts and permission sets granted on approval and revoked when the window closes.
No more permanent admin.

14 days, everything included, no card required. Try it on a sample company first - nothing to deploy in your AWS until you decide to. Sign in with a passkey - no password.
what it is + pricing, to paste into an AI or share

Request, approve in Slack, use AWS, get locked out - real footage, no cuts inside a step.

Plugs into Slack GitHub Actions PagerDuty AWS Identity Center and your own SIEM over HTTPS

Request. Approve. Auto-expire. #

Least-privilege by default. The assignment exists only for the window it's needed, then CloudGrant removes it - automatically, with a full record of who had what, when, and why.

Request

A developer requests access to a role, account or permission set - from Slack, the CLI, or the console - with a reason and a duration.

Approve

An approver gets a one-click request. Policy can auto-approve low-risk grants or require a human for sensitive ones.

Use

On approval, access is provisioned just-in-time - scoped to exactly what was asked for, nothing more.

Expire

When the window ends, CloudGrant removes the assignment. If the AWS session can outlast that window, the default is also to push a deny so further actions from an already-open session fail. A call already in flight is not cancelled; the next one is blocked.

What you get #

From the first request to the evidence an auditor asks for - all of it in the product today, none of it left for you to build.

Time-boxed access

Every grant has an expiry. Access is provisioned on approval and the assignment is removed when its window closes - zero standing privilege.

Approval workflow

Policy-driven approvals: auto-approve the routine, route the sensitive to a human, no self-approval. Approvers act in one click.

Auto-revocation

Expiry is enforced server-side, with a reconciliation sweep as backstop. The assignment is removed. When the AWS session can outlast the grant, the default is to push a deny so an already-open session's next action is refused.

Full audit trail

Every request, approval, grant and revocation is recorded and identity-stamped, attributed to the human rather than a shared role. Export it as CSV, or as a pack CloudGrant signs so a change after download is detectable. The signature is ours - it does not independently prove the human clicked approve.

Slack & CLI requests

Request access where you already work. A Slack command or the AWS credential_process - no portal context-switch required.

Break-glass

A pre-approved emergency path that grants without waiting for a human, records its own separate break-glass entry in the audit trail on top of the normal ones, and still expires on its own - so an incident never means standing admin "just in case".

On-call auto-approve

Tie approvals to your PagerDuty rotation, so the person on call gets access without waiting on a human.

Audit export to your SIEM

Stream every request, approval, grant and revocation to Splunk, Datadog, Sentinel or any HTTPS endpoint as it happens - with an optional signing secret so your receiver can tell real events from forged ones.

The same trust posture you expect from BuriCloud #

Built for the platform engineer to adopt and the person who owns the audit to sign off on.

AWS-native

Works with IAM roles, AWS accounts and IAM Identity Center permission sets - no agents to install in your accounts.

Two-role connect, never full admin

CloudGrant connects to your AWS Organization with a read-only Reader role and a separate Provisioner role scoped to only create and remove account assignments - never AdministratorAccess.

Separate admin identities

A grant is always its own admin identity - a permission set or an assumed role - never an upgrade of someone's everyday login. That is the separate-account model UK Cyber Essentials asks for, with time-boxing and a full audit trail on top.

Swiss-made, EU-hosted

Built in Switzerland. CloudGrant data sits on AWS in Frankfurt, one region, under GDPR. That is EU residency, not a claim that US cloud law cannot reach the infrastructure.

A fixed price per tier. Transparent, not quoted. #

Every package is a fixed price for your whole team, however many people join - published here, not quoted after a sales call. Start with a free 14-day trial of everything - no card required, and a sample company to click through before you connect your own AWS. Every package includes time-boxed, approved, auto-expiring access with a full audit trail.

Team

$279 $199 / mo Save 29%
fixed price, billed annually ($2,388/yr)
  • Unlimited people How many people in your workspace can request and be granted access. We never bill per person, on any package.
  • Up to 3 AWS accounts How many AWS accounts / Identity Center estates you can connect for JIT access.
  • Just-in-time access (time-boxed, approved, auto-expiring) Every grant is requested, approved, scoped, and revoked automatically when its window closes. The core engine, on every package.
  • Slack & CLI requests Request access where you already work - a Slack command or the AWS credential_process - no portal context-switch.
  • 90-day history How far back you can open the audit trail and the widest period an evidence export can cover.
  • Break-glass emergency access Pre-approved emergency access: granted without waiting for a human, recorded with its own separate break-glass audit entry, and still expiring on its own - an incident never means standing admin.
  • Multi-approver quorum Require two or more distinct approvers for sensitive access, with no self-approval.
  • Email support Support is by email on every package. Priority means your messages are answered first.
Choose Team

Cancel anytime · 14-day money-back

★ Recommended

Organization

$699 $499 / mo Save 29%
fixed price, billed annually ($5,988/yr)
  • Everything in Team, plus:
  • Org-wide (whole AWS Organization) How many AWS accounts / Identity Center estates you can connect for JIT access.
  • 1-year history How far back you can open the audit trail and the widest period an evidence export can cover.
  • Signed evidence pack The identity-stamped audit trail as one file organized for an auditor, signed by CloudGrant so a change after download is detectable. That is our attestation, not independent proof of who clicked approve. The audit log itself, and its CSV export, are on every package.
  • On-call auto-approve (PagerDuty) Tie approvals to your PagerDuty rotation, so whoever is on call gets access without waiting on a human.
  • Policy-as-code Manage eligibility and approval rules as one reviewable JSON file - export from the Rules page, test in CI with the CLI, preview and apply it back.
  • SIEM / webhook audit export Stream every request, approval, grant and revocation to your SIEM via signed webhook.
Start with Organization

Cancel anytime · 14-day money-back

Enterprise

$1,399 $999 / mo Save 29%
fixed price, billed annually ($11,988/yr)
  • Everything in Organization, plus:
  • 2+ year history How far back you can open the audit trail and the widest period an evidence export can cover.
  • SCIM / enterprise IdP provisioning Provision and de-provision users AND their group memberships automatically from your identity provider (SCIM 2.0 Users + Groups).
  • Priority email support Support is by email on every package. Priority means your messages are answered first.
Choose Enterprise

Cancel anytime · 14-day money-back

Self-Hosted

$1,999 / mo
per month, billed annually ($23,988/yr)
  • Everything in Enterprise, plus:
  • Runs in your own AWS account The Self-Hosted package runs CloudGrant entirely inside your own AWS account, for data-residency or air-gap requirements - and we deploy the first one with you.
Talk to us

We deploy the first one with you

See full pricing and package comparison

Start in minutes #

Create your CloudGrant account with just your work email - no password, no card required. Every package is free for 14 days - pick one when you're ready.

14 days, everything included, no card required. Try it on a sample company first - nothing to deploy in your AWS until you decide to. Sign in with a passkey - no password.