CIEM
Cloud Identity & Entitlement Management — the part of a CNAPP that answers “who can do what in our cloud, and how much of that do they actually use?” These PRDs describe a permission-optimization capability spanning AWS, GCP, Azure, and OCI.
The documents
The full product vision: effective-permission calculation, activity-log analysis, risk and confidence scoring, safety guardrails, and the recommendation lifecycle.
phase 2 draft v0.1 Permission Recommendation MVPThe narrow first cut: for one selected user, list assigned permissions, check X days of audit logs, and recommend keep or remove.
Reading order
Start with Phase 1 for the full problem space and product principles. Then read Phase 2 for the deliberately small MVP slice: three backend components — permission collector, log analyzer, recommendation engine — and the three questions they must answer.
The terminology used across both documents — assigned, effective, used, and unused permissions — is defined in Phase 1 · Key Concepts.