AWS IAM Governance
Identity Center, classic IAM, org multi-account, and IGA — one portal.
Connect AWS with AssumeRole + External ID (or SSO / ambient), govern with write modes, sync Identity Center and Organizations, grant and review permission-set access, remediate risky keys, enforce SoD, and export evidence — the same operating model as AD and Entra.
Product review
Interactive preview of the Rivitan portal — the same navigation and surfaces operators use, filled with realistic demo data.
AWS IAM Overview — posture score, org accounts, risky keys, findings, and governance signals (demo data).
What this portal covers
- Setup wizard · AssumeRole + External ID
- Write modes: read / request / govern / admin
- Identity Center users, groups, assignments
- Grant Access hub · temp expiry · ticket refs
- Permission-set create & curated policies
- Organization tree · env tags · prod write lock
- Classic IAM users & key create/rotate/delete
- Persistent findings · scan & remediate
- Access reviews · SoD · evidence export
- JML joiner / mover / leaver AWS steps
- Catalog publish · inventory · activity
The problem
AWS access is often managed in Console bookmarks and tribal knowledge. Identity Center assignments drift, long-lived access keys go stale, member accounts are invisible, and leaver processes forget the cloud side of the estate.
What the platform does
- Guided setup wizard: bootstrap keys, AssumeRole, External ID, health test
- Write modes: read → request → govern → admin (default read for new connections)
- Identity Center sync: users, groups, memberships, permission sets, assignments
- Unified Access hub: grant by person/group, temporary expiry, ticket refs
- Access requests with SoD evaluation (block or warn toxic permission-set pairs)
- Permission-set create with curated managed policies (lab-gated AdministratorAccess)
- Organizations discovery, env tags (lab/dev/stage/prod), prod write lock
- Member-account AssumeRole via RivitanAwsIgaRole + multi-account classic sync
- Classic IAM: create/disable/delete users; create/rotate/delete access keys
- Persistent findings: stale/never-used keys, admin users, unused roles — remediate
- AWS access reviews: Keep/Revoke over assignments; revoke via aws_permission_set fulfillment
- Evidence pack export (assignments, requests, keys, reviews, events)
- JML steps: grant (joiner), reconcile (mover), revoke (leaver)
- Publish permission sets to the entitlement catalog; inventory collectors; full audit
Who this is for
Hybrid enterprises that already trust Rivitan for Microsoft identity and need AWS IAM in the same operating model.
See AWS IAM against your own environment
Book a walkthrough and we will show this capability end to end, then talk about what a pilot would look like for your estate.