Standing AWS access is over. Get it just-in-time.
CloudGrant gives your developers time-boxed, approved, auto-expiring access to AWS - roles, accounts and permission sets granted on approval and revoked when the window closes.
No more permanent admin.
Request, approve in Slack, use AWS, get locked out - real footage, no cuts inside a step.
Request. Approve. Auto-expire. #
Least-privilege by default. The assignment exists only for the window it's needed, then CloudGrant removes it - automatically, with a full record of who had what, when, and why.
Request
A developer requests access to a role, account or permission set - from Slack, the CLI, or the console - with a reason and a duration.
Approve
An approver gets a one-click request. Policy can auto-approve low-risk grants or require a human for sensitive ones.
Use
On approval, access is provisioned just-in-time - scoped to exactly what was asked for, nothing more.
Expire
When the window ends, CloudGrant removes the assignment. If the AWS session can outlast that window, the default is also to push a deny so further actions from an already-open session fail. A call already in flight is not cancelled; the next one is blocked.
What you get #
From the first request to the evidence an auditor asks for - all of it in the product today, none of it left for you to build.
Time-boxed access
Every grant has an expiry. Access is provisioned on approval and the assignment is removed when its window closes - zero standing privilege.
Approval workflow
Policy-driven approvals: auto-approve the routine, route the sensitive to a human, no self-approval. Approvers act in one click.
Auto-revocation
Expiry is enforced server-side, with a reconciliation sweep as backstop. The assignment is removed. When the AWS session can outlast the grant, the default is to push a deny so an already-open session's next action is refused.
Full audit trail
Every request, approval, grant and revocation is recorded and identity-stamped, attributed to the human rather than a shared role. Export it as CSV, or as a pack CloudGrant signs so a change after download is detectable. The signature is ours - it does not independently prove the human clicked approve.
Slack & CLI requests
Request access where you already work. A Slack command or the AWS credential_process - no portal context-switch required.
Break-glass
A pre-approved emergency path that grants without waiting for a human, records its own separate break-glass entry in the audit trail on top of the normal ones, and still expires on its own - so an incident never means standing admin "just in case".
On-call auto-approve
Tie approvals to your PagerDuty rotation, so the person on call gets access without waiting on a human.
Audit export to your SIEM
Stream every request, approval, grant and revocation to Splunk, Datadog, Sentinel or any HTTPS endpoint as it happens - with an optional signing secret so your receiver can tell real events from forged ones.
The same trust posture you expect from BuriCloud #
Built for the platform engineer to adopt and the person who owns the audit to sign off on.
AWS-native
Works with IAM roles, AWS accounts and IAM Identity Center permission sets - no agents to install in your accounts.
Two-role connect, never full admin
CloudGrant connects to your AWS Organization with a read-only Reader role and a separate Provisioner role scoped to only create and remove account assignments - never AdministratorAccess.
Separate admin identities
A grant is always its own admin identity - a permission set or an assumed role - never an upgrade of someone's everyday login. That is the separate-account model UK Cyber Essentials asks for, with time-boxing and a full audit trail on top.
Swiss-made, EU-hosted
Built in Switzerland. CloudGrant data sits on AWS in Frankfurt, one region, under GDPR. That is EU residency, not a claim that US cloud law cannot reach the infrastructure.
A fixed price per tier. Transparent, not quoted. #
Every package is a fixed price for your whole team, however many people join - published here, not quoted after a sales call. Start with a free 14-day trial of everything - no card required, and a sample company to click through before you connect your own AWS. Every package includes time-boxed, approved, auto-expiring access with a full audit trail.
Team
- Unlimited people How many people in your workspace can request and be granted access. We never bill per person, on any package.
- Up to 3 AWS accounts How many AWS accounts / Identity Center estates you can connect for JIT access.
- Just-in-time access (time-boxed, approved, auto-expiring) Every grant is requested, approved, scoped, and revoked automatically when its window closes. The core engine, on every package.
- Slack & CLI requests Request access where you already work - a Slack command or the AWS credential_process - no portal context-switch.
- 90-day history How far back you can open the audit trail and the widest period an evidence export can cover.
- Break-glass emergency access Pre-approved emergency access: granted without waiting for a human, recorded with its own separate break-glass audit entry, and still expiring on its own - an incident never means standing admin.
- Multi-approver quorum Require two or more distinct approvers for sensitive access, with no self-approval.
- Email support Support is by email on every package. Priority means your messages are answered first.
Cancel anytime · 14-day money-back
Organization
- Everything in Team, plus:
- Org-wide (whole AWS Organization) How many AWS accounts / Identity Center estates you can connect for JIT access.
- 1-year history How far back you can open the audit trail and the widest period an evidence export can cover.
- Signed evidence pack The identity-stamped audit trail as one file organized for an auditor, signed by CloudGrant so a change after download is detectable. That is our attestation, not independent proof of who clicked approve. The audit log itself, and its CSV export, are on every package.
- On-call auto-approve (PagerDuty) Tie approvals to your PagerDuty rotation, so whoever is on call gets access without waiting on a human.
- Policy-as-code Manage eligibility and approval rules as one reviewable JSON file - export from the Rules page, test in CI with the CLI, preview and apply it back.
- SIEM / webhook audit export Stream every request, approval, grant and revocation to your SIEM via signed webhook.
Cancel anytime · 14-day money-back
Enterprise
- Everything in Organization, plus:
- 2+ year history How far back you can open the audit trail and the widest period an evidence export can cover.
- SCIM / enterprise IdP provisioning Provision and de-provision users AND their group memberships automatically from your identity provider (SCIM 2.0 Users + Groups).
- Priority email support Support is by email on every package. Priority means your messages are answered first.
Cancel anytime · 14-day money-back
Self-Hosted
- Everything in Enterprise, plus:
- Runs in your own AWS account The Self-Hosted package runs CloudGrant entirely inside your own AWS account, for data-residency or air-gap requirements - and we deploy the first one with you.
We deploy the first one with you
Start in minutes #
Create your CloudGrant account with just your work email - no password, no card required. Every package is free for 14 days - pick one when you're ready.