BEAM · ACCESS MAP

Who can reach what, right now.

See every person and every system they can touch, find access that never expires, and review each grant: keep it or revoke it, with a record of the review.

Access Map and Recertify on Business

THE USUAL WAY

The access review is a spreadsheet.

Finding the grant is only the start. The decision needs a record.

Access lists are exported from five tools and pasted into one sheet.
Nobody knows which grants were meant to be temporary.
People who left still appear in some systems.
The review happens, but there is no record of what was decided.
What you are seeing
  1. 01Every person, every system
  2. 02Switch the view
  3. 03Expiring and stale
  4. 04Keep
  5. 05Revoke
  6. 06On record
  7. 07See what happened

Example data.

How it works

See, flag, decide

01

See the map

See every person and system across AWS, GitHub and everything else Beam brokers. Switch between By person and By system.

Who has access

By person · By system

dana → orders-db · Database

Example data.

02

Flags for expiring and stale

Find grants that end soon or have no end date and are old enough to review.

1 expiring · 3 stale

orders-db · ends in 2 days

shop/app · no end date

Example data.

03

Keep or revoke, recorded

Owners and admins decide each grant. The date and kept and revoked totals form the review record.

Keep or revoke

reviewed on 4 Oct · kept 4 · revoked 2

Example data.

Explore the map

By person or by system

Search people and systems, switch the view, and filter active, expiring and past grants. Each grant shows its system, who granted it, the organisation role and when it expires.

Who has access
dana → orders-dbExpiring

Database · granted by priya · Engineer

Ends in 2 days

dana → prod-euActive

Kubernetes · granted by priya · Engineer

Ends in 20 days

lee → app-01Stale

SSH · granted by dana · Engineer

No end date

priya → AWS · shop-prodStale

Cloud account · granted by dana · Engineer

No end date

sam → #launchActive

Slack · granted by dana · Contractor

Ends in 30 days

sam → shop/appStale

GitHub · granted by dana · Contractor

No end date

Example data.

Review signals

What gets flagged

Expiring grants have an end date soon. Stale grants have no end date and have been around long enough to need a decision.

Expiring · within 7 days

dana → orders-db · ends in 2 days

Stale · no end date, 90 days old or older

sam → shop/app · 120 days old

priya → AWS · shop-prod · 95 days old

lee → app-01 · 200 days old

Example data.

Recertify

A review you can show an auditor

Owners and admins keep or revoke each active grant. The date and decisions become evidence for your periodic access reviews.

Recertify · review record

reviewed on 4 Oct · kept 4 · revoked 2

6 grants reviewed. Evidence for your periodic access reviews.

Owners and admins can recertify.

Example data.

ON THE BUSINESS PLAN

Access governance

See who has access, decide what stays, and keep the review record.

Questions

Frequently asked questions

Every person and every system they can touch across AWS, GitHub and everything else Beam brokers. Search people and systems, switch between By person and By system, and filter active, expiring or past grants. Each grant shows the system, who granted it, the organisation role and when it expires.

More in Beam

See what you run, and what it costs.

Free plan, no card needed.