Weekly: compare current IAM role assignments to baseline; detect unexpected access escalations or permission creep; alert with remediation steps.
What it does: Weekly schedule → query cloud IAM current permissions (AWS IAM roles/policies, GCP service accounts, Azure Entra) → compare to baseline/RBAC policy → code detects drift (service account has role not in baseline, principal granted overly-permissive policy) → LLM analyzes: who has unexpected access, risk level, likely cause (manual grant, config error, service account sprawl) → Slack to #security-alerts with violations and remediation.
Configure cloud IAM: AWS (IAM API), GCP (IAM API), Azure (Entra API)
Define RBAC baseline: expected role mappings (owner=admin, engineer=EC2+RDS read, dev=sandbox-only)
Set critical resources: which resources trigger high-severity alerts (prod databases, payment systems)
Configure Slack channel: #security-alerts
Apps/nodes: Schedule, HTTP request (IAM API), code node (drift comparison), Claude/OpenAI (analysis), Slack.
Credentials required: Cloud IAM API key, OpenAI account, Slack workspace.
Difficulty: Medium | Setup time: 10 minutes.
Business outcome: Permission creep caught weekly → access ↑ controlled, least-privilege ↑ enforced, compliance audits ↑ pass, security ↑.
With an active subscription, download the workflow file right from this page or your dashboard.
Choose Import from File and select the downloaded JSON. The full agent graph appears, ready to configure.
Each integration node prompts for credentials on first run. The setup guide lists every credential the agent expects.
Run once with sample input, confirm the expected output, then flip the activate toggle.
No reviews yet. Be the first.
Sign in to leave a review.
This agent — and every other in the collection — comes with your subscription. One plan, the whole catalog.
Subscribe to download