AWS Logging & Audit Foundation
A record of who did what, kept long enough to be useful and somewhere it cannot be edited.
From $299 2–4 days
Who can do what in your account, who has not used it in a year, and what to take away first.
From $299
Typically $299–$649, fixed in writing before anything starts.
What moves it up
Some of this you can check yourself, right now, for free: AWS IAM / S3 Policy Checker →
Access only ever accumulates. Nothing in AWS removes a permission because it stopped being needed, so what a two-year-old account holds is every decision anyone ever made about it: the contractor whose user was never deleted, the access key created for a script that was replaced in 2024 and still works, the policy that started as a narrow grant and got a wildcard added on a Friday. None of it is an attack. It is just that the answer to "who can delete our production database" is longer than anybody expects, and nobody has read it out loud.
aws iam get-credential-report — every user, every key, and the date each was last usedaws iam generate-service-last-accessed-details — which permissions a role has genuinely exercisedaws iam list-policies --scope Local, read for Resource "*" on mutating actionsaws organizations list-accounts, where the trust relationships cross an account boundaryNothing is removed without your sign-off on a named list, and the break-glass path is tested before the first revocation, not after it. The order is deliberate: I prove you can still get in, then things start coming out.
For a small team with one account, IAM users with MFA are workable and I will not push you off them for the sake of it. It stops being workable at the point you have a second account or a third person, because that is when the same human starts existing twice.
Yes. This work reads IAM, Organizations and access-analyzer metadata. It does not need, and does not request, permission to read the contents of a bucket or a database.
The inventory goes stale the first time somebody joins or leaves. That is why the standing procedure is one of the deliverables rather than an upsell — the cleanup is only worth paying for once if what caused it also changes.
A record of who did what, kept long enough to be useful and somewhere it cannot be edited.
From $299 2–4 days
What your account actually looks like, what breaks first, and what it is costing you to keep it that way.
From $299 2–4 days
Tell me what you are running and I will come back with a fixed price and a date. If it turns out you do not need this, I will say that instead.
Prefer to talk? Book a free call ↗ · Or hire me on Upwork ↗ · Typical reply within one business day.
Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.
One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.
You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.
Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.