# Corelamp

*/Startups/Corelamp*

## Startup Overview

This platform maps and prunes idle cloud identity roles across enterprise environments. It continuously scans cloud infrastructure to pinpoint over-permissioned accounts, dormant machine identities, and shadow admin access, directly terminating unnecessary privileges before attackers can exploit them.

Cloud security teams use the system to eliminate the massive attack surface created by credential sprawl. Where manual quarterly audits leave environments exposed for months, the software enforces least-privilege access continuously without disrupting active engineering deployments.

Unlike traditional governance suites like SailPoint or broad posture scanners like Wiz that require complex deployments and generate endless alert backlogs, this system is completely agentless and fully automated in remediation. It detects an idle role and immediately revokes it, closing access gaps in real time instead of waiting for human intervention.

## Startup Founding Hypothesis

**Approach**: that maps and prunes idle cloud identity roles
**Competitors**:
- [Wiz](/Competitors/Wiz)
- [SailPoint](/Competitors/SailPoint)
- [manual quarterly audits](/Competitors/manual_quarterly_audits)
**Differentiator2x2**: agentless and fully automated in remediation

## Startup Solution Coordinate

**Solution**: [Role Pruning Engine](/Software/Role_Pruning_Engine)

## Startup Position2x2

```mermaid
quadrantChart
title Cloud Identity Role Management
x-axis Manual Remediation --> Automated Remediation
y-axis Heavy Integration/Agents --> Agentless Integration
quadrant-1 Zero-Touch Auto-Pruning
quadrant-2 Agentless Alerting
quadrant-3 Manual Governance
quadrant-4 Automated but Heavy
Wiz: [0.45, 0.85]
SailPoint: [0.30, 0.25]
Manual quarterly audits: [0.10, 0.15]
Corelamp: [0.90, 0.85]
```

## Startup Offer

**Proof**:
- Targeting mid-market fintechs aiming to reduce their IAM attack surface by 40% in two weeks.
- Aiming for zero production downtime incidents caused by automated role pruning during initial deployment.
- Designed to replace 40+ hours of manual quarterly compliance auditing per engineering team.
**Tiers**:
- Name: Single Cloud · Price: ~$500–$1,500/mo · Inclusions: Continuous mapping and pruning for 1 cloud environment, up to 5,000 IAM roles, and daily automated remediation cycles.
- Name: Multi-Cloud Growth · Price: ~$2,500–$5,000/mo · Inclusions: Continuous mapping and pruning across up to 3 cloud environments, up to 25,000 IAM roles, and custom Slack/Jira approval routing.
- Name: Enterprise Fabric · Price: enterprise: ~$60k–$120k/yr · Inclusions: Unlimited cloud environments, unlimited IAM roles, dedicated compliance reporting, and custom RBAC mapping.
**Guarantee**: If Corelamp fails to identify and safely revoke at least 20% of your idle, over-permissioned cloud roles within the first 30 days without breaking production workloads, you receive a full refund for that month.
**Business Function**: ProvideService
**Objection Handlers**:
- Automated pruning will break production workloads: Corelamp is designed to run in a read-only simulation mode for 14 days, proving the exact impact of every revoked permission before any live changes are executed.
- We already use Wiz or SailPoint: Wiz alerts you to the problem and SailPoint handles human identity; Corelamp is built specifically to automate the actual remediation of non-human cloud roles without requiring an agent.
- We require explicit approvals before revoking access: Corelamp intends to integrate directly with Slack and Jira, routing pruning recommendations to the resource owner for one-click approval before execution.
- Installing an agent introduces security risks: Corelamp operates entirely agentless, utilizing cross-account IAM read roles to map dependencies and orchestrate remediation.
**Pricing Architecture**: Tiered
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Clinical and direct, prioritizing exact identity permissions over security alarmism.
**Tagline**: Remove idle cloud access roles with zero installed agents.
**Icon Concept**: Badge
**Palette Intent**: institutional-cool
**Visual Identity**: Deep navy and slate tones anchor the interface, using sharp monospace typography to cleanly display complex permission trees and access logs.
**Archetype Reference**: the-ruler

## Startup Buyer Chain

**Chain**: Corelamp → Cloud Security Engineer → Enterprise CISO
**Gtm Motion**: Acquires initial users through a read-only, single-environment IAM risk assessment that maps dormant permissions, then expands across the enterprise footprint by upselling the write-access automated pruning and cross-cloud enforcement capabilities.
**Agent Channel**: Intended to publish its identity-revocation API in the LangChain tool registry and AWS Bedrock agent directories, allowing autonomous SOC agents to discover and trigger role pruning during active threat containment.
**Primary Channel**: AWS Marketplace and GCP Marketplace searches by IAM administrators looking for automated least-privilege enforcement tools, alongside discovery via targeted sponsorships in practitioner newsletters like tl;dr sec.

## Startup Customer Journey

```mermaid
flowchart LR; N1[AWS Marketplace] --> N2[Read-Only IAM Assessment]; N2 --> N3[Dormant Permission Map]; N3 --> N4[Pruning Simulation Engine]; N4 --> N5[Automated Role Pruning]; N5 --> N6[Slack Approval Integration]; N6 --> N7[Multi-Cloud Enforcement]; N7 --> N8[SOC Agent Directory];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- A 14-day read-only simulation pilot within a single cloud environment to map up to 5,000 IAM roles and prove the existence of at least 20% idle permissions without altering live infrastructure.
- A 30-day active remediation pilot integrating with the client's Slack workspace to validate the one-click approval workflow and confirm successful non-human role pruning with zero downtime.
**Target Metrics**:
- Target: 20% minimum reduction in idle and over-permissioned cloud IAM roles within the first 30 days.
- Aim: 0 production workload interruptions caused by automated remediation cycles following the 14-day read-only simulation.
- Target: 40 hours of engineering time saved per team during quarterly compliance audits.
- Aim: 100% agentless mapping of cloud environments utilizing cross-account IAM read roles.
**Target Case Studies**:
- A mid-market fintech company managing rapid cloud expansion, aiming to map non-human identity dependencies and safely revoke over-permissioned roles without interrupting live financial transactions.
- A growth-stage B2B SaaS provider preparing for SOC2 compliance, targeting a transition from manual quarterly spreadsheet audits to continuous agentless IAM mapping and automated reporting.
- A multi-cloud enterprise operating across AWS and GCP, seeking to route permission pruning recommendations directly to resource owners via Jira for one-click approval instead of centralized manual bottlenecks.
**Testimonial Targets**:
- VP of Engineering expressing relief that the 14-day read-only simulation accurately predicted impact, allowing safe role pruning without breaking production workloads.
- Head of Cloud Security highlighting the elimination of manual follow-ups because the platform routes remediation approvals directly to resource owners in Slack.
- Compliance Director validating that the continuous mapping and dedicated reporting replaced their stressful manual audit processes with verifiable, real-time IAM posture data.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Automated remediation incorrectly prunes a critical production IAM role, causing severe customer downtime and immediate reputational collapse. · Mitigation Status: unmitigated
- Severity: high · Description: Security and compliance teams refuse to grant the extensive write permissions required for automated remediation to a young vendor. · Mitigation Status: in-progress
- Severity: high · Description: Incumbents like Wiz or SailPoint replicate the automated pruning feature and bundle it for free within their existing enterprise platforms. · Mitigation Status: unmitigated
- Severity: moderate · Description: Undocumented changes to major cloud provider IAM APIs break the agentless mapping engine, causing temporary visibility gaps. · Mitigation Status: mitigated

## Startup Competitors

- [Wiz](/Competitors/Wiz) — Incumbent
- [SailPoint](/Competitors/SailPoint) — Incumbent
- [Manual Quarterly Audits](/Competitors/Manual_Quarterly_Audits) — Status Quo
- [Orca Security](/Competitors/Orca_Security) — CNAPP Platform
- [CyberArk](/Competitors/CyberArk) — Legacy PAM

## Startup Story Brand

**Hero**:
- **Need**: to be the architect of a hardened infrastructure, not a rubber-stamper for Jira tickets
- **Want**: to eliminate the attack surface from thousands of over-privileged cloud identities
- **Identity**: the cloud security lead at a mid-market fintech
**Plan**:
- Step: Deploy simulation · Detail: Run the agentless engine in read-only mode for 14 days to map every live identity dependency.
- Step: Confirm impact · Detail: Review the automated impact report to verify that pruning idle roles won't disrupt production workloads.
- Step: Approve remediation · Detail: Execute one-click role revocation via Slack or Jira to permanently shrink your cloud attack surface.
**Guide**:
- **Empathy**: Zero-day exploits are won in minutes — but your remediation cycle is trapped in quarterly spreadsheets.
**Problem**:
- **Villain**: identity bloat
- **External**: manual quarterly audits in SailPoint fail to catch idle non-human roles across AWS and GCP environments
- **Internal**: you feel responsible for an inevitable breach hidden in thousands of unused permissions
- **Philosophical**: Engineering expertise belongs in building product, not in auditing dead IAM roles.
**Success**: Your cloud environment maintains a least-privilege state automatically, with every idle role pruned and zero production downtime.
**One Liner**: Every quarter, cloud security leads struggle with manual identity audits. Corelamp automates the mapping and pruning of idle roles so you reduce your attack surface without breaking production.
**Positioning**:
- **So That**: automatically revoke idle IAM roles without using agents
- **Unlike**: Wiz and manual quarterly audits
- **For Whom**: Cloud security leads at mid-market fintechs
- **Category**: Automated Cloud Identity Remediation
**Call To Action**:
- **Direct**: Prune idle roles
- **Transitional**: View sample permission map
**Failure Stakes**:
- unauthorized lateral movement during breaches
- forty hours of manual auditing per team
- failed compliance for over-privileged roles
**Transformation**:
- **To**: free to harden infrastructure, no longer stuck doing the drudgery
- **From**: a security lead buried in IAM spreadsheets
**Controlling Idea**: Cloud security requires automated remediation of idle identities, not just more alerts.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Every quarter, cloud security leads struggle with manual identity audits. Corelamp automates the mapping and pruning of idle roles so you reduce your attack surface without breaking production.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 0efde644916f9806

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Automated Cloud Identity Remediation for Cloud security leads at mid-market fintechs. Unlike Wiz and manual quarterly audits — automatically revoke idle IAM roles without using agents.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: e5e5c8efe2274115

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: manual quarterly audits in SailPoint fail to catch idle non-human roles across AWS and GCP environments
Solution: Every quarter, cloud security leads struggle with manual identity audits. Corelamp automates the mapping and pruning of idle roles so you reduce your attack surface without breaking production.
Customer: Cloud security leads at mid-market fintechs
Unlike: Wiz and manual quarterly audits
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: eac16d617a3124cf

## Startup Token M E D D P I C C

**Pain**: manual quarterly audits in SailPoint fail to catch idle non-human roles across AWS and GCP environments
**Metrics**: Target: Your cloud environment maintains a least-privilege state automatically, with every idle role pruned and zero production downtime.
**Rendered**: Pain: manual quarterly audits in SailPoint fail to catch idle non-human roles across AWS and GCP environments
Economic buyer: Cloud Security Engineer
Metrics: Target: Your cloud environment maintains a least-privilege state automatically, with every idle role pruned and zero production downtime.
Competition: Wiz and manual quarterly audits
**Mechanism**: spine-derived-v1
**Competition**: Wiz and manual quarterly audits
**Economic Buyer**: Cloud Security Engineer
**Vocab Fingerprint**: fe8cb7e6715d3a53

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Automated Cloud Identity Remediation for Cloud security leads at mid-market fintechs

Cloud security leads at mid-market fintechs — manual quarterly audits in SailPoint fail to catch idle non-human roles across AWS and GCP environments Every quarter, cloud security leads struggle with manual identity audits. Corelamp automates the mapping and pruning of idle roles so you reduce your attack surface without breaking production.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 066bab5b9e6e5284

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Automated Cloud Identity Remediation. Every quarter, cloud security leads struggle with manual identity audits. Corelamp automates the mapping and pruning of idle roles so you reduce your attack surface without breaking production. Serves Cloud security leads at mid-market fintechs.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 95f3b28917de06bb

## Neighborhood

### Candidate solutions

- [Tax Season Capacity Bottlenecks](/Problems/Tax_Season_Capacity_Bottlenecks) — candidate solution for · Problems

### Composed of

- [Tax Intake Triage Service](/Services/Tax_Intake_Triage_Service) — composes · Services
- [Unstructured Document Parser API](/Software/Unstructured_Document_Parser_API) — composes · Software
- [Capacity Dispatch Service](/Services/Capacity_Dispatch_Service) — composes · Services
- [Complexity Triage Agent](/Agents/Complexity_Triage_Agent) — composes · Agents
- [Workload Rebalancing Agent](/Agents/Workload_Rebalancing_Agent) — composes · Agents
- [Staff Capacity Sync SDK](/Software/Staff_Capacity_Sync_SDK) — composes · Software
- [Practice Management API](/Software/Practice_Management_API) — composes · Software
- [Vision Extraction Engine](/Software/Vision_Extraction_Engine) — composes · Software
- [Document Complexity Worker](/Agents/Document_Complexity_Worker) — composes · Agents
- [Capacity Routing Agent](/Agents/Capacity_Routing_Agent) — composes · Agents

### What it offers

- [Role Pruning Engine](/Software/Role_Pruning_Engine) — offers · Software
- [Capacity Dispatch Agent](/Agents/Capacity_Dispatch_Agent) — offers · Agents
- [Corelamp Triage Agent](/Agents/Corelamp_Triage_Agent) — offers · Agents

### Competitors

- [Orca Security](/Competitors/Orca_Security) — competes with · Competitors
- [SailPoint](/Competitors/SailPoint) — competes with · Competitors
- [Manual Quarterly Audits](/Competitors/Manual_Quarterly_Audits) — competes with · Competitors
- [Wiz](/Competitors/Wiz) — competes with · Competitors
- [CyberArk](/Competitors/CyberArk) — competes with · Competitors
- [Thomson Reuters Practice CS](/Competitors/Thomson_Reuters_Practice_CS) — competes with · Competitors
- [Master Spreadsheets](/Competitors/Master_Spreadsheets) — competes with · Competitors
- [Offshore Contractors](/Competitors/Offshore_Contractors) — competes with · Competitors
- [CCH Axcess Practice](/Competitors/CCH_Axcess_Practice) — competes with · Competitors
- [Canopy Practice Management](/Competitors/Canopy_Practice_Management) — competes with · Competitors
- [Manual Spreadsheet Exports](/Competitors/Manual_Spreadsheet_Exports) — competes with · Competitors
- [Offshore Seasonal Contractors](/Competitors/Offshore_Seasonal_Contractors) — competes with · Competitors
- [Seasonal Offshore Contractors](/Competitors/Seasonal_Offshore_Contractors) — competes with · Competitors
- [Excel Master Spreadsheets](/Competitors/Excel_Master_Spreadsheets) — competes with · Competitors
- [Offshore Contractor Swarms](/Competitors/Offshore_Contractor_Swarms) — competes with · Competitors
- [Seasonal Offshore Labor](/Competitors/Seasonal_Offshore_Labor) — competes with · Competitors
- [Offshore Temp Contractors](/Competitors/Offshore_Temp_Contractors) — competes with · Competitors
- [Offshore Temporary Labor](/Competitors/Offshore_Temporary_Labor) — competes with · Competitors
- [Thomson Reuters Practice](/Competitors/Thomson_Reuters_Practice) — competes with · Competitors
- [Master Excel Schedules](/Competitors/Master_Excel_Schedules) — competes with · Competitors
- [Offshore Staffing Agencies](/Competitors/Offshore_Staffing_Agencies) — competes with · Competitors
- [Offshore Temporary Contractors](/Competitors/Offshore_Temporary_Contractors) — competes with · Competitors
- [Offshore Tax Contractors](/Competitors/Offshore_Tax_Contractors) — competes with · Competitors
- [Manual Master Spreadsheets](/Competitors/Manual_Master_Spreadsheets) — competes with · Competitors

### Embodies

- [Software](/Theses/Software) — embodies · Theses
- [Agent](/Theses/Agent) — embodies · Theses

### Who it serves

- [Accounting Firm](/CompanyTypes/Accounting_Firm) — serves · CompanyTypes

### Similar Startups

- [Permoster](/Startups/Permoster) — similar · Startups
- [Atonyx](/Startups/Atonyx) — similar · Startups
- [Posept](/Startups/Posept) — similar · Startups
- [Novia](/Startups/Novia) — similar · Startups
- [Spaceintractable](/Startups/Spaceintractable) — similar · Startups
- [Hororus](/Startups/Hororus) — similar · Startups
- [Atomnon](/Startups/Atomnon) — similar · Startups
- [Accirm](/Startups/Accirm) — similar · Startups
- [Direridian](/Startups/Direridian) — similar · Startups
- [Aegispark](/Startups/Aegispark) — similar · Startups
- [Acceam](/Startups/Acceam) — similar · Startups
- [Chronecurity](/Startups/Chronecurity) — similar · Startups
- [Acaspoint](/Startups/Acaspoint) — similar · Startups
- [Coordinatorfield](/Startups/Coordinatorfield) — similar · Startups
- [Venturenexus](/Startups/Venturenexus) — similar · Startups
- [Domill](/Startups/Domill) — similar · Startups
- [Verow](/Startups/Verow) — similar · Startups
- [Accaze](/Startups/Accaze) — similar · Startups
- [Leap](/Startups/Leap) — similar · Startups
- [Weldedrock](/Startups/Weldedrock) — similar · Startups
