CIEM

Cloud Identity & Entitlement Management — the part of a CNAPP that answers “who can do what in our cloud, and how much of that do they actually use?” These PRDs describe a permission-optimization capability spanning AWS, GCP, Azure, and OCI.

The documents

Reading order

Start with Phase 1 for the full problem space and product principles. Then read Phase 2 for the deliberately small MVP slice: three backend components — permission collector, log analyzer, recommendation engine — and the three questions they must answer.

The terminology used across both documents — assigned, effective, used, and unused permissions — is defined in Phase 1 · Key Concepts.


Back to top

© 2026 Ayush Aggarwal. Notes are living documents — they change as I learn, update, and reorganize them.