# Domill

*/Startups/Domill*

## Startup Overview

This security engine resolves identity and access management (IAM) misconfigurations by directly applying least-privilege policies across cloud environments. It maps actual usage patterns against existing permissions to identify over-provisioned human and machine identities.

Cloud security and infrastructure teams traditionally rely on passive posture management tools like Wiz or Prisma Cloud, which generate alerts that must be routed through manual ticketing workflows. This process creates a structural delay between discovering an exposure and resolving it, leaving critical infrastructure vulnerable during the transition.

Instead of adding to an alert queue, the system closes the remediation gap through direct policy execution without requiring manual approval loops. Operating on an outcome-priced model, it charges based on the specific misconfigurations it permanently remediates, aligning the cost of security strictly with the elimination of risk.

## Startup Founding Hypothesis

**Approach**: that resolves IAM misconfigurations by applying least-privilege policies
**Competitors**:
- [Wiz](/Competitors/Wiz)
- [Prisma Cloud](/Competitors/Prisma_Cloud)
- [manual ticketing workflows](/Competitors/manual_ticketing_workflows)
**Differentiator2x2**: outcome-priced and capable of direct policy execution without manual approval loops

## Startup Solution Coordinate

**Solution**: [IAM Remediation Service](/Services/IAM_Remediation_Service)

## Startup Position2x2

```mermaid
quadrantChart
    title IAM Misconfiguration Resolution
    x-axis Resource Priced --> Outcome-Priced
    y-axis Manual Approval Loops --> Direct Policy Execution
    quadrant-1 Automated Resolution
    quadrant-2 Execution Tools
    quadrant-3 Alert Generators
    quadrant-4 Managed Services
    Wiz: [0.15, 0.35]
    Prisma Cloud: [0.25, 0.40]
    Manual Ticketing Workflows: [0.10, 0.10]
    Domill: [0.85, 0.85]
```

## Startup Offer

**Proof**:
- Aiming to eliminate 100% of unused standing cloud permissions for mid-market engineering organizations.
- Targeting a 60-second time-to-remediate for new IAM drift, bypassing traditional manual Jira queues entirely.
- Designing to achieve zero production downtime during automated policy right-sizing events.
**Tiers**:
- Name: Pay-Per-Resolution · Price: ~$15–$30 per resolved misconfiguration · Inclusions: Direct execution of least-privilege policies with automated rollback capabilities, billed strictly per successful closure of an over-provisioned IAM role.
- Name: Retained Remediation · Price: ~$2,500–$5,000/mo base + ~$5–$10 per resolution · Inclusions: Discounted metered rate for continuous IAM drift correction across up to 5 cloud environments, including prioritized concurrent execution and SIEM integration.
- Name: Enterprise Unlimited · Price: ~$40k–$80k/yr · Inclusions: Flat unmetered automated remediation for multi-cloud enterprise footprints, covering unlimited direct IAM policy executions and custom namespace whitelisting.
**Guarantee**: If an automated least-privilege policy executed by Domill disrupts an active, legitimate service dependency, the system is designed to trigger an instant rollback and we will credit the cost of that remediation.
**Business Function**: ProvideService
**Objection Handlers**:
- Automated direct execution will break our production apps if it removes a required permission. -> Domill is designed to simulate every proposed policy against the past 30 days of cloud access logs to verify safety before executing.
- Our compliance framework requires a human audit trail for all IAM changes. -> Every automated resolution is designed to write a deterministic, compliant log directly to your SIEM detailing the exact pre- and post-state of the role.
- Pricing per outcome will bankrupt us because we have thousands of existing misconfigurations. -> The initial baseline cleanup is capped at a fixed one-time onboarding rate; metered outcome pricing only applies to ongoing drift detection.
**Pricing Architecture**: UsageMeter
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Direct and uncompromising, prioritizing rapid execution over bureaucratic caution.
**Tagline**: Enforce least-privilege access instantly without manual approval loops.
**Icon Concept**: keycard
**Palette Intent**: institutional-cool
**Visual Identity**: Deep navy backgrounds and stark sans-serif typography pair with brushed steel accents to reflect the unyielding nature of access-control boundaries.
**Archetype Reference**: the-ruler

## Startup Buyer Chain

**Chain**: B2B → Cloud Security Architect → DevOps Teams
**Gtm Motion**: Acquires initial usage through single-environment IAM risk assessments that highlight over-privileged roles and misconfigurations. Expands via outcome-based pricing that charges per automatically remediated policy, growing revenue as deployment covers additional cloud accounts and identity providers.
**Agent Channel**: Designed to list in the LangChain tool registry and the OpenAI schema directory as a direct remediation capability, allowing autonomous SOC agents to discover and invoke Domill's policy execution API during automated incident response workflows.
**Primary Channel**: Technical search engines and GitHub repository discovery for terms like 'automated AWS IAM remediation', capturing DevSecOps engineers actively looking to replace manual Jira security ticketing workflows.

## Startup Customer Journey

```mermaid
flowchart LR; A[GitHub Repository] --> B[IAM Risk Assessment Tool]; B --> C[Least-Privilege Policy]; C --> D[Usage Meter]; D --> E[Enterprise Multi-Cloud]; E --> F[Autonomous SOC Agent];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day baseline cleanup in a single staging environment: Aims to execute least-privilege policies on 50 over-provisioned roles, validating the automated rollback trigger if a simulated dependency is disrupted.
- 30-day continuous drift monitoring pilot: Targets the detection and automated remediation of newly introduced IAM misconfigurations within 60 seconds, proving the efficacy of the usage-metered ongoing protection.
**Target Metrics**:
- Target: 100% elimination of unused standing IAM permissions
- Target: 60-second time-to-remediate for new IAM drift incidents
- Target: Zero production downtime events triggered by automated policy right-sizing
- Aim: 100% deterministic SIEM log coverage for automated resolution events
**Target Case Studies**:
- Mid-market SaaS engineering director: Aims to demonstrate the complete elimination of unused standing cloud permissions during a capped-fee baseline cleanup without a single disrupted service dependency.
- Enterprise FinTech cloud security lead: Targets the transition from manual Jira ticket queues to automated 60-second IAM drift remediation across multiple cloud environments, supported by deterministic SIEM logging.
- Series C infrastructure manager: Aims to prove the safety of direct least-privilege execution by highlighting Domill's 30-day access log simulation and automated rollback capabilities in a live production environment.
**Testimonial Targets**:
- VP of Engineering: Validates the safety of the platform by confirming that the 30-day log simulation prevents automated right-sizing from breaking active service dependencies.
- Cloud Security Architect: Confirms that the deterministic pre- and post-state logs written directly to the SIEM successfully pass internal compliance framework audits.
- DevOps Lead: Expresses relief that the pay-per-resolution model paired with the automated 60-second remediation completely replaces the manual IAM configuration Jira queue.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Automated permission revocation breaks an undocumented production service, resulting in a severe outage and immediate customer churn. · Mitigation Status: in-progress
- Severity: high · Description: Enterprise security teams refuse to grant the extensive read-write IAM permissions required for the platform to execute policies without manual approval. · Mitigation Status: unmitigated
- Severity: moderate · Description: Outcome-based pricing leads to unpredictable revenue as customers dispute the quantifiable value of automatically revoked inactive permissions. · Mitigation Status: in-progress
- Severity: moderate · Description: Incumbents like Wiz or Prisma Cloud bundle automated IAM remediation into their existing platforms, undercutting the standalone value proposition. · Mitigation Status: unmitigated

## Startup Competitors

- [Wiz](/Competitors/Wiz) — Incumbent
- [Prisma Cloud](/Competitors/Prisma_Cloud) — Incumbent
- [Manual Ticketing Workflows](/Competitors/Manual_Ticketing_Workflows) — Status Quo
- [Orca Security](/Competitors/Orca_Security) — CNAPP Competitor
- [Sonrai Security](/Competitors/Sonrai_Security) — CIEM Provider

## Startup Solution Stack

- [IAM Remediation Service](/Services/IAM_Remediation_Service) — Service-as-Software
- [Entitlement Analysis Agent](/Agents/Entitlement_Analysis_Agent) — Agent
- [Policy Execution Agent](/Agents/Policy_Execution_Agent) — Agent
- [State Reconciliation Engine](/Software/State_Reconciliation_Engine) — Software
- [Cloud Policy API](/Software/Cloud_Policy_API) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the strategist who hardens infrastructure, not the bottleneck chasing Jira approvals
- **Want**: to eliminate over-provisioned IAM roles without the friction of manual ticketing
- **Identity**: the cloud security lead at a mid-market engineering firm
**Plan**:
- Step: Select Scope · Detail: Identify the cloud environments and namespaces where you want to enforce least-privilege standards.
- Step: Validate Simulation · Detail: Review the pre-flight check where we prove the new policy won't break your existing service dependencies.
- Step: Automate Enforcement · Detail: Deploy direct execution to resolve misconfigurations instantly, bypassing the manual approval loop.
**Guide**:
- **Empathy**: Does your IAM remediation still stall in developer backlogs for weeks while standing privileges remain exposed?
**Problem**:
- **Villain**: manual ticketing workflows
- **External**: Fixing a single over-privileged role in AWS or Azure requires a manual Jira ticket, a developer review, and hours of waiting while Prisma Cloud alerts continue to pile up.
- **Internal**: You feel like a glorified secretary for security alerts instead of an engineer building resilient systems.
- **Philosophical**: Cloud infrastructure was built for elastic scale, not bureaucratic stagnation.
**Success**: Your cloud footprint reaches a constant state of least-privilege with zero manual tickets and an instant rollback safety net.
**One Liner**: Every day, cloud security leads struggle with mounting IAM alerts and slow manual approvals. Domill executes least-privilege policies directly so you can harden your infrastructure in seconds without the ticketing friction.
**Positioning**:
- **So That**: enforce least-privilege without waiting for manual developer approvals
- **Unlike**: manual ticketing and Wiz alerts
- **For Whom**: Cloud security leads at mid-market firms
- **Category**: Automated IAM Remediation for Cloud Engineering
**Call To Action**:
- **Direct**: Resolve a misconfiguration
- **Transitional**: View simulation report
**Failure Stakes**:
- Critical credential theft
- Audit non-compliance
- Production downtime from drift
**Transformation**:
- **To**: free to architect secure systems, no longer stuck chasing developer approvals
- **From**: a security lead buried in Jira tickets
**Controlling Idea**: Cloud security should be enforced at the speed of the cloud itself.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Every day, cloud security leads struggle with mounting IAM alerts and slow manual approvals. Domill executes least-privilege policies directly so you can harden your infrastructure in seconds without the ticketing friction.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 399de6e6c56228c6

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Automated IAM Remediation for Cloud Engineering for Cloud security leads at mid-market firms. Unlike manual ticketing and Wiz alerts — enforce least-privilege without waiting for manual developer approvals.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: a6b9d86910cd6d0b

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Fixing a single over-privileged role in AWS or Azure requires a manual Jira ticket, a developer review, and hours of waiting while Prisma Cloud alerts continue to pile up.
Solution: Every day, cloud security leads struggle with mounting IAM alerts and slow manual approvals. Domill executes least-privilege policies directly so you can harden your infrastructure in seconds without the ticketing friction.
Customer: Cloud security leads at mid-market firms
Unlike: manual ticketing and Wiz alerts
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 81acafe060653dfc

## Startup Token M E D D P I C C

**Pain**: Fixing a single over-privileged role in AWS or Azure requires a manual Jira ticket, a developer review, and hours of waiting while Prisma Cloud alerts continue to pile up.
**Metrics**: Target: Your cloud footprint reaches a constant state of least-privilege with zero manual tickets and an instant rollback safety net.
**Rendered**: Pain: Fixing a single over-privileged role in AWS or Azure requires a manual Jira ticket, a developer review, and hours of waiting while Prisma Cloud alerts continue to pile up.
Economic buyer: Cloud Security Architect
Metrics: Target: Your cloud footprint reaches a constant state of least-privilege with zero manual tickets and an instant rollback safety net.
Competition: manual ticketing and Wiz alerts
**Mechanism**: spine-derived-v1
**Competition**: manual ticketing and Wiz alerts
**Economic Buyer**: Cloud Security Architect
**Vocab Fingerprint**: 1fab0cfd88e7c60c

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Automated IAM Remediation for Cloud Engineering for Cloud security leads at mid-market firms

Cloud security leads at mid-market firms — Fixing a single over-privileged role in AWS or Azure requires a manual Jira ticket, a developer review, and hours of waiting while Prisma Cloud alerts continue to pile up. Every day, cloud security leads struggle with mounting IAM alerts and slow manual approvals. Domill executes least-privilege policies directly so you can harden your infrastructure in seconds without the ticketing friction.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 6e25c763eb4951e6

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Automated IAM Remediation for Cloud Engineering. Every day, cloud security leads struggle with mounting IAM alerts and slow manual approvals. Domill executes least-privilege policies directly so you can harden your infrastructure in seconds without the ticketing friction. Serves Cloud security leads at mid-market firms.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 7a5bb9bc2af9c26f

## Neighborhood

### Candidate solutions

- [ABET Accreditation Data Collection](/Problems/ABET_Accreditation_Data_Collection) — candidate solution for · Problems
- [Pending Warranty Claim Receivables](/Problems/Pending_Warranty_Claim_Receivables) — candidate solution for · Problems
- [Schedule Warehouse Cross-Docking](/Problems/Schedule_Warehouse_Cross-Docking) — candidate solution for · Problems

### Composed of

- [LMS Integration SDK](/Software/LMS_Integration_SDK) — composes · Software
- [Artifact Extraction Worker](/Agents/Artifact_Extraction_Worker) — composes · Agents
- [Outcome Correlation Agent](/Agents/Outcome_Correlation_Agent) — composes · Agents
- [Accreditation Audit Engine](/Services/Accreditation_Audit_Engine) — composes · Services
- [Multimodal Parsing API](/Software/Multimodal_Parsing_API) — composes · Software
- [Artifact Extraction Agent](/Agents/Artifact_Extraction_Agent) — composes · Agents
- [Curriculum Alignment Agent](/Agents/Curriculum_Alignment_Agent) — composes · Agents
- [Engineering Format API](/Software/Engineering_Format_API) — composes · Software
- [Artifact Anonymization Engine](/Software/Artifact_Anonymization_Engine) — composes · Software
- [Compliance Dossier Service](/Services/Compliance_Dossier_Service) — composes · Services
- [Entitlement Analysis Agent](/Agents/Entitlement_Analysis_Agent) — composes · Agents
- [Policy Execution Agent](/Agents/Policy_Execution_Agent) — composes · Agents
- [State Reconciliation Engine](/Software/State_Reconciliation_Engine) — composes · Software
- [Cloud Policy API](/Software/Cloud_Policy_API) — composes · Software

### Embodies

- [Agent](/Theses/Agent) — embodies · Theses
- [Service-as-Software](/Theses/Service-as-Software) — embodies · Theses

### What it offers

- [Evidence Agent](/Agents/Evidence_Agent) — offers · Agents
- [IAM Remediation Service](/Services/IAM_Remediation_Service) — offers · Services

### Competitors

- [Canvas LMS](/Competitors/Canvas_LMS) — competes with · Competitors
- [Manual Spreadsheet Mapping](/Competitors/Manual_Spreadsheet_Mapping) — competes with · Competitors
- [Watermark](/Competitors/Watermark) — competes with · Competitors
- [Canvas](/Competitors/Canvas) — competes with · Competitors
- [SharePoint](/Competitors/SharePoint) — competes with · Competitors
- [manual spreadsheets](/Competitors/manual_spreadsheets) — competes with · Competitors
- [Watermark Assessment Suite](/Competitors/Watermark_Assessment_Suite) — competes with · Competitors
- [Gradescope](/Competitors/Gradescope) — competes with · Competitors
- [Manual Spreadsheet Tracking](/Competitors/Manual_Spreadsheet_Tracking) — competes with · Competitors
- [HelioCampus](/Competitors/HelioCampus) — competes with · Competitors
- [Shared Departmental Folders](/Competitors/Shared_Departmental_Folders) — competes with · Competitors
- [Watermark Platforms](/Competitors/Watermark_Platforms) — competes with · Competitors
- [Generic LMS Gradebooks](/Competitors/Generic_LMS_Gradebooks) — competes with · Competitors
- [Watermark Assessment](/Competitors/Watermark_Assessment) — competes with · Competitors
- [Manual Shared Folders](/Competitors/Manual_Shared_Folders) — competes with · Competitors
- [Spreadsheet Rubric Mapping](/Competitors/Spreadsheet_Rubric_Mapping) — competes with · Competitors
- [spreadsheet mapping](/Competitors/spreadsheet_mapping) — competes with · Competitors
- [manual departmental spreadsheets](/Competitors/manual_departmental_spreadsheets) — competes with · Competitors
- [SharePoint folders](/Competitors/SharePoint_folders) — competes with · Competitors
- [manual compliance spreadsheets](/Competitors/manual_compliance_spreadsheets) — competes with · Competitors
- [Prisma Cloud](/Competitors/Prisma_Cloud) — competes with · Competitors
- [Manual Ticketing Workflows](/Competitors/Manual_Ticketing_Workflows) — competes with · Competitors
- [Wiz](/Competitors/Wiz) — competes with · Competitors
- [Orca Security](/Competitors/Orca_Security) — competes with · Competitors
- [Sonrai Security](/Competitors/Sonrai_Security) — competes with · Competitors

### Similar Startups

- [Accirm](/Startups/Accirm) — similar · Startups
- [Posept](/Startups/Posept) — similar · Startups
- [Aegispark](/Startups/Aegispark) — similar · Startups
- [Zenithember](/Startups/Zenithember) — similar · Startups
- [Novia](/Startups/Novia) — similar · Startups
- [Aspenmere](/Startups/Aspenmere) — similar · Startups
- [Weldedrock](/Startups/Weldedrock) — similar · Startups
- [Atonyx](/Startups/Atonyx) — similar · Startups
- [Zenentinel](/Startups/Zenentinel) — similar · Startups
- [Leap](/Startups/Leap) — similar · Startups
- [Auroraleap](/Startups/Auroraleap) — similar · Startups
- [Dalatigue](/Startups/Dalatigue) — similar · Startups
- [Brookill](/Startups/Brookill) — similar · Startups
- [Corelamp](/Startups/Corelamp) — similar · Startups
- [Verow](/Startups/Verow) — similar · Startups
- [Permoster](/Startups/Permoster) — similar · Startups
- [Puonarch](/Startups/Puonarch) — similar · Startups
- [Archos](/Startups/Archos) — similar · Startups
- [Staborus](/Startups/Staborus) — similar · Startups
- [Aurossom](/Startups/Aurossom) — similar · Startups
