All integrations
AWS
Cloud
AWS IAM Identity Center
Permission sets across every AWS account
Clavra assigns AWS permission sets for a fixed time instead of leaving people in admin groups. When someone asks for AdministratorAccess, Clavra shows what that set can do in plain words and suggests a smaller set when one fits the ticket.
What Clavra can change
Account assignments of permission sets you mark as requestable. It cannot create or edit permission sets.
Before you connect
Deploy the CloudFormation stack from the setup page into your management account. It creates one role that Clavra assumes, with an external ID.
Category
Cloud
Sync
Reads accounts and permission sets hourly. Assigns and removes permission sets per grant.
Setup time
20 min