Why this is flagged
- First sign-in from this laptop, 11 minutes ago
- Not on call this week. His usual role is PowerUser
- Admin can change IAM policies and read billing exports
Just-in-time access for AWS, Okta, databases and code
Clavra is an access-request inbox. Approve, narrow or deny with the risk in front of you, and every grant expires on schedule.
Demo data · nothing leaves your browser
Halden
parcelwise
MORROW HEALTH
Tessel Pay
Kestrel Insurance
fieldnote
Brightline Labs
OAKHARBOR
What it checks
Clavra pulls the on-call schedule, the ticket, the device and the person’s usual access, then spells out what the role would really open. You decide in seconds instead of opening five tabs.
Signal 01
Passed
Clavra reads PagerDuty and Opsgenie schedules. On-call engineers can be approved automatically for the systems their rotation covers, for the length of the shift.
priya.raman on call until 22:00 sre-primary
Signal 02
Review
Each request is compared with the person’s own history and with their team. A data analyst asking for write access to production stands out straight away.
t.wilk asks read on FINANCE team usually has FINANCE_REPORTING
Signal 03
Flagged
AdministratorAccess sounds routine. Clavra spells it out: it can change IAM policies and read billing exports. When a smaller role fits the ticket, Clavra suggests it.
suggest kms-rotate for 1h instead of AdministratorAccess for 8h
2m 41s
Median time from request to decision across Clavra customers.
0
Standing admin accounts left at Halden six weeks after rollout.
100%
Of grants carry an end time, including break-glass access.
7 yrs
Signed audit log retention, exportable to your SIEM.
Audit log
Who asked, who approved, what was granted, for how long and why. Every line is signed and chained to the one before it, so nobody can quietly edit history. Auditors get a CSV. You get your Friday back.
halden / audit / today
Writing
01 · Ask
A Slack command, the web inbox or the API. The reason and the ticket travel with the request, so nobody has to chase context.
/access prod-payments-db read-write 2h INC-4471
02 · Decide
Risk signals sit next to the buttons. Narrow a request to the smaller role Clavra suggests, or pick a shorter window with one tap.
approve narrow to 1h deny
03 · Expire
Clavra removes the grant when time is up, even at 3 a.m., and writes the expiry to the log. There is nothing to remember and nothing to clean up.
15:02:13 expired on schedule
Integrations
OK
Okta
Groups, app assignments and admin roles
AWS
AWS IAM Identity Center
Permission sets across every AWS account
GCP
Google Cloud
IAM roles on projects and folders
PG
PostgreSQL
Database roles on RDS, Cloud SQL and self-hosted
SF
Snowflake
Warehouse roles and sensitive schemas
GH
GitHub
Repository and organization roles
“We had 212 people with standing admin in AWS. Six weeks after Clavra we had nine, and every one of them is on the platform team.”
MR
Maren Roth
Head of Security, Halden
Halden, six weeks in
212 → 9
people with standing admin in AWS. Everyone else asks for access when they need it and it ends on its own.
Book a demo
A 30-minute walkthrough with your own systems. Most teams connect Okta and AWS in an afternoon.