# Just-In-Time Provisioning for DevOps

*/Opportunities/Just-In-Time_Provisioning_for_DevOps*

## Opportunity Overview

**Wedge**: The beachhead is temporary production database access for on-call engineers debugging active incidents. This niche offers fast proof of value by eliminating a high-stress bottleneck during outages while immediately reducing severe data exfiltration risks. From this initial foothold, the system expands horizontally to govern temporary access to cloud provider consoles, Kubernetes clusters, and internal administrative tooling.
**Timing**: The shift toward Zero Trust architectures and ephemeral infrastructure makes static credentials obsolete and non-compliant with modern security standards. Concurrently, AI agents can now reliably parse natural language access requests in Slack and cross-reference them against ticketing systems to validate intent before executing API commands.
**Why This I C P**: Platform Engineering and DevOps teams own both the infrastructure and the automation mandate, experiencing the pain of manual access requests directly in their daily operational velocity. They possess the technical authority to deploy infrastructure-level integrations and the budget to eliminate their own productivity bottlenecks.
**Size Of Prize**: There are approximately 40,000 mid-to-large tech-forward enterprises globally managing complex cloud infrastructure. At an average annual spend of $25,000 for infrastructure access management tooling and equivalent security operations labor, the addressable prize is roughly $1B.
**Gap Narrative**: Platform engineering and DevOps teams rely on manual Jira tickets or static, long-lived credentials to grant infrastructure access, creating operational bottlenecks and severe security vulnerabilities. They require a system that grants temporary, least-privilege access automatically based on real-time context like active incidents or assigned tickets without requiring human intervention.
**Defensibility**: Defensibility builds through deep workflow lock-in and compliance reliance. Once the platform becomes the central routing layer for all engineering access requests and the primary system of record for SOC2 and ISO27001 audit logs, ripping it out requires retraining all engineering staff and rebuilding the organization's entire security compliance architecture.
**Why This Thesis**: An Agentic workflow approach fits perfectly because access provisioning requires evaluating unstructured context, such as Slack messages and PagerDuty alerts, against strict structured rules like IAM policies. An agent handles the cognitive load of context validation and executes the deterministic API calls to grant and subsequently revoke access.

## Opportunity Linked Thesis

**Thesis**: [Software](/Theses/Software)

## Opportunity Linked I C P

**Icp**: [Software Enterprise](/CompanyTypes/Software_Enterprise)

## Opportunity Market Sizing

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**S A M**: ~$800M-1.2B among cloud-native software enterprises with dedicated DevOps functions
**S O M**: ~$30M-50M realistic capture over 3 years
**T A M**: ~50k mid-to-large tech enterprises globally × ~$40k-60k/yr on DevOps access management ≈ ~$2B-3B
**Growth Rate**: ~25-30%/yr, driven by zero-trust security mandates and ephemeral cloud infrastructure adoption
**Paid Comparable Spend**: ~$150k-250k/yr per enterprise on dedicated IAM support engineers, custom credential rotation scripts, and over-provisioned static cloud access licenses

## Opportunity Incumbents

- [HashiCorp Vault](/Products/HashiCorp_Vault) — Tool
- [Teleport Access Platform](/Products/Teleport_Access_Platform) — Open-Source
- [CyberArk Secrets Manager](/Products/CyberArk_Secrets_Manager) — Tool
- [Custom Shell Scripts](/Products/Custom_Shell_Scripts) — DIY
- [Manual Jira Tickets](/Products/Manual_Jira_Tickets) — DIY
- [Okta Server Access](/Products/Okta_Server_Access) — Tool

## Opportunity Win Conditions

**Kill Thresholds**:
- Time-to-provision exceeds 15 seconds during live incidents
- Auto-approval rate remains below 50% after 30 days of policy tuning
- Fewer than 10 daily active engineers using the integration by day 45
- Zero seat expansion from pilot to general engineering within 90 days
**Leading Metrics**:
- Time-to-provision from request to active credential
- Percentage of access requests auto-approved by policy
- Number of static credentials revoked post-deployment
- Daily active engineers initiating ephemeral workflows
- Mean time to credential expiry
**What Proves Right**: DevOps engineers request access via CLI or Slack and receive ephemeral credentials within seconds. The platform auto-approves over 80% of routine requests based on contextual policies, eliminating manual Jira ticket queues for IT. Customers expand seat licenses from the initial security pilot to the broader engineering organization within 60 days.
**What Proves Wrong**: DevOps teams bypass the tool to manually share static root credentials because the just-in-time workflow introduces latency during live incident response. Security administrators block deployment due to missing granular audit logs or missing identity provider integrations. The auto-approval rate remains low, forcing IT to manually review and approve the majority of access requests.

## Opportunity Build Profile

**Hardest Part**: Guaranteeing absolute access revocation across distributed infrastructure even during network partitions or target system outages. Failing to reliably terminate a session creates an immediate, critical security vulnerability.
**Min Viable Scope**: A Slack-native application that triggers AWS STS to generate short-lived credentials for pre-defined IAM roles based on single-peer approval. Exclude GCP, Azure, on-premise Kubernetes, native database protocol proxying, and multi-tier compliance routing.
**Cold Start Problem**: The platform requires deep integrations into dozens of infrastructure targets to replace existing PAM solutions. Break this by focusing solely on one acute pain point, like production AWS RDS access, and hardcoding that single integration for the initial design partners.
**Time To First Value**: 1-2 days to deploy the agent, map existing IAM roles, and process the first Slack approval request
**Data Moat Available**: false
**Technical Difficulty**: Moderate

## Neighborhood

### Incumbent in

- [Teleport Access Platform](/Products/Teleport_Access_Platform) — incumbent in · Products
- [Manual Jira Tickets](/Products/Manual_Jira_Tickets) — incumbent in · Products
- [Okta Server Access](/Products/Okta_Server_Access) — incumbent in · Products
- [Custom Shell Scripts](/Products/Custom_Shell_Scripts) — incumbent in · Products
- [CyberArk Secrets Manager](/Products/CyberArk_Secrets_Manager) — incumbent in · Products
- [HashiCorp Vault](/Products/HashiCorp_Vault) — incumbent in · Products

### Applies thesis

- [Software Enterprise](/CompanyTypes/Software_Enterprise) — applies thesis · CompanyTypes

### Embodies

- [Software](/Theses/Software) — embodies · Theses

### Similar Opportunities

- [Automated Review for DevOps Teams](/Opportunities/Automated_Review_for_DevOps_Teams) — similar · Opportunities
- [Managed Auth Operations](/Opportunities/Managed_Auth_Operations) — similar · Opportunities
- [Predictive Role Mining for Security](/Opportunities/Predictive_Role_Mining_for_Security) — similar · Opportunities
- [Access Policy Auditor](/Opportunities/Access_Policy_Auditor) — similar · Opportunities
- [Security Architecture Auditing](/Opportunities/Security_Architecture_Auditing) — similar · Opportunities
- [AI Systems Engineering](/Skills/Systems_Evaluation/Opportunities/AI_Systems_Engineering) — similar · Opportunities
- [Fractional Systems Engineer](/Opportunities/Fractional_Systems_Engineer) — similar · Opportunities
- [Autonomous L1 Responder](/Opportunities/Autonomous_L1_Responder) — similar · Opportunities
- [Algorithmic Access Auditing for VMOs](/Opportunities/Algorithmic_Access_Auditing_for_VMOs) — similar · Opportunities
- [Identity Lifecycle Automation](/Opportunities/Identity_Lifecycle_Automation) — similar · Opportunities
- [Autonomous Provisioning for Enterprise IT](/Opportunities/Autonomous_Provisioning_for_Enterprise_IT) — similar · Opportunities
- [System Design Engine](/Opportunities/System_Design_Engine) — similar · Opportunities
- [Contextual Access Granting for Healthcare](/Opportunities/Contextual_Access_Granting_for_Healthcare) — similar · Opportunities
- [AI Release Auditing For DevOps](/Opportunities/AI_Release_Auditing_For_DevOps) — similar · Opportunities
- [Audit Request Fulfillment](/Opportunities/Audit_Request_Fulfillment) — similar · Opportunities
- [Day-One Provisioning Agent](/Opportunities/Day-One_Provisioning_Agent) — similar · Opportunities
- [Downtime Recovery Agent](/Opportunities/Downtime_Recovery_Agent) — similar · Opportunities
- [Onboarding Orchestration Agent](/Opportunities/Onboarding_Orchestration_Agent) — similar · Opportunities
- [Ephemeral Environment Agent](/Opportunities/Ephemeral_Environment_Agent) — similar · Opportunities
- [Cloud Cost Remediation](/Opportunities/Cloud_Cost_Remediation) — similar · Opportunities
