Just-in-time access for AWS, Okta, databases and code

Access that ends on its own.

Access that ends on its own.

Clavra is an access-request inbox. Approve, narrow or deny with the risk in front of you, and every grant expires on schedule.

Clavra
/Halden
Requests4GrantsReviewsAudit
Active grants3
Decided today23
Median decision2m 41s
HK

Waiting on you

4 open
Asked for 8hCHG-1193“Rotating the KMS key before tonight's deploy.”
Why this is flagged
  • First sign-in from this laptop, 11 minutes ago
  • Not on call this week. His usual role is PowerUser
  • Admin can change IAM policies and read billing exports
Rotating a KMS key needs kms-rotate, not admin.
JK moveA approveD deny
People
Groups
Systems
PRPriya RamanSRE, on call
TWTomasz WilkData analyst
DODaniel OyelaranPlatform engineer
LFLucía FerrerInfrastructure
AMAma MensahSupport lead
oncall-sre
data-analysts
Just-in-time
platform-eng
support-t2
AWShalden-prodAWS account 4471-0826
PGprod-payments-dbPostgres 16 on RDS
SFFINANCESnowflake database
GHhalden/infraGitHub repository
OKOkta adminIdentity provider
ZDZendeskSupport desk
Admin · new device
Opens IAM and billing exports
Audit logEvery decision, signed and kept for 7 years.
13:22:00hana.kapprovedpriya.raman halden-prod PowerUser 4h INC-4468#7a80
13:36:38clavrarevokedk.osei prod-payments-db read left the company at 13:30#78b4
13:48:02policyapprovedama.mensah Zendesk agent 8h rule support-default#58a8
13:55:40clavraexpiredt.wilk FINANCE_REPORTING read ended on schedule#d5e5
14:00:57hana.kdeniedl.ferrer Okta admin super admin use break-glass instead#cbc5
Clavra
/Halden
Requests4GrantsReviewsAudit
Active grants3
Decided today23
Median decision2m 41s
HK

Waiting on you

4 open
Asked for 8hCHG-1193“Rotating the KMS key before tonight's deploy.”
Why this is flagged
  • First sign-in from this laptop, 11 minutes ago
  • Not on call this week. His usual role is PowerUser
  • Admin can change IAM policies and read billing exports
Rotating a KMS key needs kms-rotate, not admin.
JK moveA approveD deny
People
Groups
Systems
PRPriya RamanSRE, on call
TWTomasz WilkData analyst
DODaniel OyelaranPlatform engineer
LFLucía FerrerInfrastructure
AMAma MensahSupport lead
oncall-sre
data-analysts
Just-in-time
platform-eng
support-t2
AWShalden-prodAWS account 4471-0826
PGprod-payments-dbPostgres 16 on RDS
SFFINANCESnowflake database
GHhalden/infraGitHub repository
OKOkta adminIdentity provider
ZDZendeskSupport desk
Admin · new device
Opens IAM and billing exports
Audit logEvery decision, signed and kept for 7 years.
13:22:00hana.kapprovedpriya.raman halden-prod PowerUser 4h INC-4468#7a80
13:36:38clavrarevokedk.osei prod-payments-db read left the company at 13:30#78b4
13:48:02policyapprovedama.mensah Zendesk agent 8h rule support-default#58a8
13:55:40clavraexpiredt.wilk FINANCE_REPORTING read ended on schedule#d5e5
14:00:57hana.kdeniedl.ferrer Okta admin super admin use break-glass instead#cbc5

Try it: approve, deny or narrow a request. The graph and the audit log update as you decide.

Try it: approve, deny or narrow a request. The graph and the audit log update as you decide.

Demo data · nothing leaves your browser

Security teams deciding access in Clavra

Security teams deciding access in Clavra

  • Halden

  • parcelwise

  • MORROW HEALTH

  • Tessel Pay

  • Kestrel Insurance

  • fieldnote

  • Brightline Labs

  • OAKHARBOR

What it checks

Every request arrives with the facts to judge it.

Clavra pulls the on-call schedule, the ticket, the device and the person’s usual access, then spells out what the role would really open. You decide in seconds instead of opening five tabs.

Signal 01

Passed

Is this person on call right now?

Clavra reads PagerDuty and Opsgenie schedules. On-call engineers can be approved automatically for the systems their rotation covers, for the length of the shift.

priya.raman on call until 22:00 sre-primary

Signal 02

Review

Is this their usual access?

Each request is compared with the person’s own history and with their team. A data analyst asking for write access to production stands out straight away.

t.wilk asks read on FINANCE team usually has FINANCE_REPORTING

Signal 03

Flagged

What does this role really open?

AdministratorAccess sounds routine. Clavra spells it out: it can change IAM policies and read billing exports. When a smaller role fits the ticket, Clavra suggests it.

suggest kms-rotate for 1h instead of AdministratorAccess for 8h

2m 41s

Median time from request to decision across Clavra customers.

0

Standing admin accounts left at Halden six weeks after rollout.

100%

Of grants carry an end time, including break-glass access.

7 yrs

Signed audit log retention, exportable to your SIEM.

Audit log

The audit log writes itself.

Who asked, who approved, what was granted, for how long and why. Every line is signed and chained to the one before it, so nobody can quietly edit history. Auditors get a CSV. You get your Friday back.

halden / audit / today

Writing

13:22:00 hana.k approved priya.raman halden-prod 4h

13:22:00 hana.k approved priya.raman halden-prod 4h

13:36:38 clavra revoked k.osei payments-db offboarded

13:36:38 clavra revoked k.osei payments-db offboarded

13:55:40 clavra expired t.wilk FINANCE on schedule

13:55:40 clavra expired t.wilk FINANCE on schedule

14:00:57 hana.k denied l.ferrer Okta super admin

14:00:57 hana.k denied l.ferrer Okta super admin

14:02:12 hana.k narrowed d.oyelaran admin → kms-rotate

14:02:12 hana.k narrowed d.oyelaran admin → kms-rotate

14:02:13 clavra granted kms-rotate halden-prod 1h

14:02:13 clavra granted kms-rotate halden-prod 1h

15:02:13 clavra expired kms-rotate halden-prod ended

15:02:13 clavra expired kms-rotate halden-prod ended

Ask in Slack. Decide in one click. Never chase a revoke again.

Ask in Slack. Decide in one click. Never chase a revoke again.

01 · Ask

People ask where they already work

A Slack command, the web inbox or the API. The reason and the ticket travel with the request, so nobody has to chase context.

/access prod-payments-db read-write 2h INC-4471

02 · Decide

You approve, narrow or deny

Risk signals sit next to the buttons. Narrow a request to the smaller role Clavra suggests, or pick a shorter window with one tap.

approve narrow to 1h deny

03 · Expire

Access ends on schedule

Clavra removes the grant when time is up, even at 3 a.m., and writes the expiry to the log. There is nothing to remember and nothing to clean up.

15:02:13 expired on schedule

“We had 212 people with standing admin in AWS. Six weeks after Clavra we had nine, and every one of them is on the platform team.”

MR

Maren Roth

Head of Security, Halden

Halden, six weeks in

212 → 9

people with standing admin in AWS. Everyone else asks for access when they need it and it ends on its own.

Book a demo

Put an end date on every grant.

A 30-minute walkthrough with your own systems. Most teams connect Okta and AWS in an afternoon.

Every grant ends. Every decision is on the record.

Every grant ends. Every decision is on the record.

Every grant ends. Every decision is on the record.

Clavra

Just-in-time access for engineering and security teams. People ask, you decide with the facts in front of you, and access ends on its own.

Live right now

1,284 grants open

0 without an end time

Log kept 7 years

© 2026 Clavra. Made with Framer.

SOC 2 Type II · ISO 27001 · GDPR

Create a free website with Framer, the website builder loved by startups, designers and agencies.