Opportunities
Access Policy Auditor
Connected through 8 “incumbent in” links and 2 “latent gaps” links.
Opportunities
Opportunities
Connected through 8 “incumbent in” links and 2 “latent gaps” links.
Structure
Demand side
Build difficulty
Hardest Part
Resolving inherited and implied permissions across complex cloud environments into a deterministic effective access graph without generating massive volumes of false positives.
Min Viable Scope
Focus strictly on AWS IAM for cloud-native startups to output a prioritized list of over-privileged roles alongside auto-generated Terraform remediation code. Explicitly exclude multi-cloud support, Kubernetes RBAC, and formal compliance framework reporting.
Cold Start Problem
The rule engine requires a vast library of real-world edge-case misconfigurations to validate its logic reliably. Break this by releasing a narrowly scoped open-source CLI scanner for a single service to validate the core graph logic on developer machines before building the commercial platform.
Time To First Value
15 minutes after connecting a read-only cross-account IAM role
Data Moat Available
false
Technical Difficulty
High
Build profile
The gap
Wedge
The initial beachhead targets AWS IAM policy reviews for growth-stage startups preparing for their first major compliance audit. This niche feels acute pain from impending deadlines and operates primarily in a single cloud environment. Once the system owns AWS IAM compliance, it expands horizontally to cover identity providers like Okta and then downstream SaaS application access policies.
Timing
LLMs with large context windows now successfully parse and reason over thousands of lines of JSON-based IAM policies simultaneously. Previously, deterministic rule engines could only check against static benchmarks, failing to catch logical loopholes created by overlapping group memberships.
Why This ICP
Mid-market cloud-native companies face enterprise-grade compliance audits like SOC2 but lack the dedicated IAM headcount of large enterprises. They experience immediate pain from audit deadlines and adopt automated tooling faster than legacy organizations burdened by on-premise constraints.
Size Of Prize
~30,000 mid-to-large enterprises in the US and EU spend an average of $40,000 annually on IAM auditing consultants and manual review labor. This yields an addressable market of $1.2 billion.
Gap Narrative
Cloud security teams cannot decipher complex, overlapping IAM policies across infrastructure and SaaS environments. Existing posture management tools flag gross misconfigurations but fail to reason about granular, compounded permissions or business context. This leaves organizations over-provisioned and blind to lateral movement risks until an audit or breach occurs.
Defensibility
Defensibility stems from workflow lock-in and a proprietary mapping graph of identity relationships. As the system continuously ingests policy changes and remediation approvals, it builds a bespoke knowledge base of the organization's intended access architecture. Replacing the tool requires abandoning this historical context and manually rebuilding the baseline of acceptable access exceptions.
Why This Thesis
Service-as-Software fits perfectly because IAM auditing is currently purchased as an intermittent consulting service or handled via manual sprints. An AI agent that autonomously reads policies, maps attack paths, and generates remediation pull requests directly replaces outsourced auditor labor rather than adding another dashboard.
Overview
Sized prize
IllustrativeIllustrative targets and order-of-magnitude estimates — not an achieved track record. This Thing is concept-stage; real figures come from live data once operating.
SAM
~$800M - $1.2B (US and EU mid-market to enterprise financial firms)
SOM
~$20M - $50M
TAM
~35k global mid-to-large financial institutions × ~$60k/yr ≈ ~$2.1B
Growth Rate
~18-24%/yr, driven by tightening financial cybersecurity regulations (e.g., DORA, SEC rules) and hybrid cloud identity sprawl
Paid Comparable Spend
~$100k - $300k/yr on external audit consultants, manual IT access review labor, and legacy identity governance add-ons
Market sizing
How you know
Kill Thresholds
Leading Metrics
What Proves Right
Customers connect their primary identity directory and generate a compliant access review report without manual mapping. Compliance officers log in weekly to remediate orphaned accounts and excessive permissions rather than batching work for quarterly audits. Early adopters sign annual contracts at the $60,000 price point to offset external audit consulting hours.
What Proves Wrong
Security teams block deployment because they refuse to grant the auditor read access to their core identity providers. The policy engine flags too many false positive privilege violations, forcing auditors to manually verify every alert in Excel. Deployments stall for months because the platform cannot parse legacy on-premise mainframe permissions.
Win conditions