Cloud Permissions Firewall
One click to least privilege

- Role
- Principal Product Designer
- Client
- Sonrai Security
- Year
- 2025
- Practice
- Product designEnterprise SaaSData density
Every enterprise cloud footprint carries thousands of over-permissioned identities, dormant accounts, unused services, and open regions. Each one is a standing invitation for lateral movement, and traditional IAM tooling asks security teams to hand-audit them role by role — a program measured in quarters, not sprints.
The Cloud Permissions Firewall closes that gap by enforcing least privilege from actual cloud activity. Unused permissions are stripped, dormant identities are quarantined, and sensitive services, regions, and third parties are blocked at the guardrail layer — driven by AWS Service Control Policies and their Azure and GCP equivalents rather than one-off role edits.
The design challenge was making that automation feel safe to operators who own production. Every enforcement action is reversible, previewed against real usage, and paired with a ChatOps request-and-approval path so developers can reclaim access in minutes instead of filing a ticket. Least privilege becomes a default posture the platform maintains, not a project the security team perpetually reopens.
Inside the product
One design system, every enforcement surface.
Identities, services, third parties, and regions all share the same table, status, and action language — so the interface stays consistent as the product grows, and operators can move between guardrails without re-learning the interaction model.

