Cloud IAMSonrai Security2025

Cloud Permissions Firewall

One click to least privilege

Cloud Permissions Firewall
Role
Principal Product Designer
Client
Sonrai Security
Year
2025
Practice
Product designEnterprise SaaSData density

Every enterprise cloud footprint carries thousands of over-permissioned identities, dormant accounts, unused services, and open regions. Each one is a standing invitation for lateral movement, and traditional IAM tooling asks security teams to hand-audit them role by role — a program measured in quarters, not sprints.

The Cloud Permissions Firewall closes that gap by enforcing least privilege from actual cloud activity. Unused permissions are stripped, dormant identities are quarantined, and sensitive services, regions, and third parties are blocked at the guardrail layer — driven by AWS Service Control Policies and their Azure and GCP equivalents rather than one-off role edits.

The design challenge was making that automation feel safe to operators who own production. Every enforcement action is reversible, previewed against real usage, and paired with a ChatOps request-and-approval path so developers can reclaim access in minutes instead of filing a ticket. Least privilege becomes a default posture the platform maintains, not a project the security team perpetually reopens.

Inside the product

One design system, every enforcement surface.

Identities, services, third parties, and regions all share the same table, status, and action language — so the interface stays consistent as the product grows, and operators can move between guardrails without re-learning the interaction model.

Services page with the service inspector panel open on Amazon GuardDuty
Services page with the inspector panel open — sensitive permissions, per-account status, and one-click protect actions in a single, scannable surface.
Home page with the Regions modal for enabling and disabling AWS regions
Regions modal on the home page — the same table + status + action pattern reused for geography, so operators only learn the model once.
Built at Sonrai Security2025Sonrai Security

Next case study

WALLy — Accidental Mascot

View