Traditional IAM provisioning creates accounts, assigns groups, and grants roles. But it does not govern the complete lifecycle of cloud access.
For organizations operating across AWS, Microsoft Azure, Google Cloud, SaaS, and on-premises systems, the real question is not simply whether an identity has been provisioned. It is whether the organization can prove:
-
Who can access each resource
-
What actions they can perform
-
Why the access exists
-
Who approved it
-
How long it should remain active
-
Whether it is being used
-
When it should be removed
Citadel Identity360 provides the governance layer needed to answer these questions across human, machine, and AI identities.
Why provisioning alone is not enough
Cloud access is rarely created through a single assignment. Effective access can result from direct permissions, nested groups, inherited roles, policy conditions, temporary sessions, resource policies, permission boundaries, and cross-account or cross-tenant relationships.
A user removed from a directory group may still retain a direct cloud role. A contractor may be deactivated while a service account they created continues to operate. A role intended for one resource may be approved at subscription, project, or account level. Two seemingly acceptable permissions may create a toxic combination when used together.
Provisioning tools can confirm that an identity exists and has received a role. They do not necessarily establish whether that access remains appropriate.
Citadel Identity360 turns cloud permissions into governed business entitlements that are visible, owned, reviewable, and removable.
Govern effective access—not just assignments
A list of users and roles does not show what the cloud actually permits.
Effective access is the result of evaluating every applicable permission, inheritance path, condition, boundary, session, and deny rule. It must account for both the identity receiving access and the resource being accessed.
With Citadel Identity360, the governance record can connect:
-
The identity and its lifecycle state
-
The cloud provider, account, subscription, project, or tenant
-
The native role, policy, or permission set
-
Direct and inherited access paths
-
Conditions and limiting controls
-
The business owner and technical owner
-
The request, justification, and approver
-
Start and expiration dates
-
Usage and risk signals
-
Review and remediation history
Instead of showing only that “Jane belongs to Developers,” reviewers can understand Jane’s effective permissions, the resources within scope, why the access exists, and whether it is still required.
One governance layer across AWS, Azure, and GCP
Each cloud provider represents access differently. Citadel Identity360 preserves provider-specific detail while presenting it through a consistent governance model.
AWS
Governance must consider IAM users, groups, roles, identity and resource policies, permissions boundaries, service control policies, session policies, resource shares, and IAM Identity Center assignments.
Citadel Identity360 can bring these entitlement relationships into a business-oriented governance process that adds ownership, justification, certification, lifecycle controls, and remediation.
Microsoft Azure
Azure access can be inherited across management groups, subscriptions, resource groups, and individual resources. Governance must also distinguish between Entra group membership, access packages, active role assignments, eligible privileged roles, service principals, and managed identities.
Citadel Identity360 connects these technical assignments to the people, business purposes, approvals, and lifecycle events behind them.
Google Cloud
GCP access may result from organization-, folder-, project-, or resource-level bindings. IAM Conditions, deny policies, principal access boundaries, groups, service accounts, and workload identities can all affect the final result.
Citadel Identity360 incorporates these relationships into a governed entitlement record so business owners can decide whether the resulting access is justified.
Beyond request and approval
Cloud governance should not end when an access ticket is closed.
Citadel Identity360 supports an ongoing governance cycle:
-
Discover: Collect identities, entitlements, ownership information, lifecycle state, and relevant usage evidence.
-
Understand: Reconstruct effective access across direct, inherited, temporary, group-derived, and resource-based grants.
-
Contextualize: Associate access with owners, business purposes, projects, sponsors, duration, and data sensitivity.
-
Govern: Apply role models, lifecycle policies, segregation-of-duties controls, approval requirements, and managed exceptions.
-
Certify: Present reviewers with meaningful effective-access context rather than raw technical assignments.
-
Remediate: Remove, modify, or expire inappropriate access while preserving evidence of the decision and resulting change.
This continuous process helps prevent privilege creep, orphaned access, unnecessary service-desk work, and gaps in audit evidence.
IAM enforces. CIEM analyzes. Citadel governs.
Provider IAM remains responsible for evaluating policies and enforcing access. CIEM capabilities can help discover cloud permissions, analyze privilege, and identify potentially excessive access.
Citadel Identity360 adds the enterprise governance layer: authoritative identity context, lifecycle automation, entitlement ownership, approvals, access certification, segregation of duties, exception management, and audit evidence.
These capabilities are complementary:
-
IAM enforces access.
-
CIEM identifies and analyzes cloud entitlements.
-
Citadel Identity360 governs the business decision and entitlement lifecycle.
Citadel does not replace AWS IAM, Azure RBAC, or Google Cloud IAM. It makes their entitlements governable across the enterprise.
Governing non-human identities
Employees are no longer the only identities with access to critical systems.
Service accounts, managed identities, workload identities, API identities, automation pipelines, bots, and AI agents frequently hold broad and persistent permissions. These identities can remain active long after the project or person responsible for them has moved on.
Citadel Identity360 brings non-human identities into the governance model by establishing:
-
A responsible business and technical owner
-
A documented purpose
-
Permitted systems, resources, tools, and data
-
Credential age and rotation requirements
-
Usage and activity evidence
-
Review and expiration requirements
-
An emergency suspension or termination path
AI agents require additional context, including approved tools, accessible data domains, operating boundaries, version information, logging requirements, and human approval points.
Treating these identities as governed entities helps close one of the fastest-growing access-control blind spots.
A practical starting point
Organizations do not need to transform every cloud environment at once. Citadel recommends starting with one measurable governance outcome.
A phased approach can include:
-
Connect representative AWS, Azure, and GCP environments in read-only mode.
-
Inventory identities, effective entitlements, ownership, and usage evidence.
-
Reconcile identity records, nested groups, and non-human identity owners.
-
Prioritize privileged, external, dormant, orphaned, and unusually broad access.
-
Remediate clear risks with owner notification and rollback procedures.
-
Establish governed roles and access packages for repeatable access.
-
Automate joiner, mover, and leaver processes from authoritative sources.
-
Introduce risk-based reviews for privileged and sensitive access.
-
Expand governance to service accounts, workloads, bots, and AI agents.
The goal is not a perfect entitlement model on day one. It is to make cloud access progressively more visible, accountable, reviewable, and removable.
The Citadel difference
Provisioning creates access. Citadel Identity360 governs whether that access should exist.
By bringing human, machine, and AI identities into a centralized governance model, Citadel helps organizations understand effective access, assign accountability, automate identity lifecycles, detect identity risk, manage segregation of duties, and preserve evidence for audit.
The next step is not another disconnected security dashboard. It is a read-only inventory of cloud entitlements, a clear ownership model, and a governance roadmap focused on the organization’s highest-risk access.
With Citadel Identity360, every entitlement can have an owner, a purpose, a duration, and a defensible decision.