Secure

IAM: one answer to who can do what, everywhere

Cluster RBAC, cloud roles and platform permissions in one model, with time-bound elevation instead of standing admin and access reviews that produce revocations.

Short answer

What is IAM?

DevOpsArk IAM is the module that models and governs access across Kubernetes clusters, cloud accounts and the DevOpsArk platform itself: least-privilege roles, time-bound elevation, periodic access review and a complete audit trail of privileged action.

Why it matters

What IAM is for

The conditions this module removes. If none of these are familiar, you probably do not need it yet.

  • Permissions are spread across cluster RBAC, three cloud IAM systems and the CI tool, so "who can delete production" has no single answer.
  • Standing administrator access is granted for an incident in 2023 and never removed.
  • Access review is a spreadsheet exercise that ends with everything being approved.
  • Leavers keep cluster credentials because revocation happens in one system and not the others.
  • Privileged actions are logged per system, so reconstructing an incident means joining four audit logs by hand.
How it works

IAM builds one model of effective access across Kubernetes RBAC, cloud provider IAM and DevOpsArk platform roles, so a question about a person or a service account is answered once rather than per system. Standing privilege is replaced with time-bound elevation: a request states what is needed and why, an approver grants it for a fixed period, and it expires automatically. Access reviews are generated from actual usage (showing which granted permissions have never been exercised), which makes revocation an easy decision rather than a contested one. Every privileged action taken through the platform is recorded in one trail, so reconstructing what happened during an incident does not require joining logs from four systems.

Capabilities

What IAM does

The 7 capabilities that make up IAM.

Unified effective-access model

Cluster RBAC, cloud IAM and platform roles resolved into one answer per identity.

Time-bound elevation

Privilege is requested with a reason, approved for a fixed window and expires on its own.

Usage-informed access review

Reviews show which permissions were actually used, so unused grants are revoked without argument.

Role templates by function

Roles defined for platform engineer, developer, on-call and auditor rather than assembled per person.

Unified privileged audit

One trail of privileged action across clusters, clouds and the platform.

Break-glass with accountability

Emergency access is available, recorded, time-limited and reviewed afterwards rather than blocked or invisible.

Coordinated offboarding

Revocation across every connected system as one action, with confirmation per system.

Architecture

How IAM fits together

Identity sources
OktaEntra IDGoogle WorkspaceSAML / OIDC
IAM
Effective access modelElevation workflowReview enginePrivileged audit
Targets
Kubernetes RBACAWS IAMAzure RBACGCP IAMPlatform roles
IAM architecture within the DevOpsArk control plane.

Outcomes

  • Access questions have one answer instead of four partial ones.
  • Standing administrator access goes away without blocking urgent work.
  • Access reviews produce revocations because they are based on usage.
  • Offboarding is complete and provable.
  • Incident reconstruction reads one audit trail.
How to use it

Using IAM, step by step

The path from connecting a source to getting value, in the order it happens.

  1. 1
    Connect identity

    Attach the identity provider and the systems whose access should be governed.

  2. 2
    Model effective access

    RBAC, cloud IAM and platform roles are resolved into one view per identity.

  3. 3
    Replace standing privilege

    Define elevation paths with approvers and maximum durations.

  4. 4
    Review against usage

    Periodic reviews show which grants were exercised and which were not.

  5. 5
    Audit and offboard

    Privileged action is recorded centrally; revocation runs across all systems at once.

Use cases

Where teams apply IAM

Security

Remove standing admin

Replace permanent elevated roles with time-bound elevation that expires automatically.

Compliance

Run a meaningful access review

Review against actual usage rather than a list of grants nobody can evaluate.

Platform engineering

Answer who can delete a namespace

Resolve effective access across RBAC and cloud IAM in one query.

IT operations

Offboard completely

Revoke across every connected system in one action, with per-system confirmation.

Supported technologies

What IAM works with

Named integrations link to their own page. The rest are supported runtimes and formats.

Do not see your stack? DevOpsArk works over standard interfaces: the Kubernetes API, OCI images, OpenTelemetry and cloud provider APIs, so most environments are supported without a bespoke connector. Ask us about yours.
FAQ

IAM: frequently asked questions

The 7 questions teams ask most often before adopting IAM.

See IAM against your own environment

A 30-minute walkthrough with a platform engineer, not a sales deck. Bring a cluster and a problem.