Hey everyone,
I've been deep in the weeds of our PAM (Privileged Access Management) evaluation for the last quarter, trying to move beyond our brittle homegrown vault scripts and manual JIT (Just-in-Time) access requests. The goal is a proper GitOps-friendly, auditable pipeline for privilege. In my last round of vendor demos, **Clutch Security** came up repeatedly, especially for their focus on developer experience and cloud-native workflows.
I've watched their overview webinars and the API looks clean, but I'm always skeptical until I can run it through a real-world, hands-on trial. I'm talking about:
* Testing their Terraform provider to see if we can truly manage roles and policies as code.
* Pushing ephemeral access requests through our existing Slack/Opsgenie alerting channels.
* Simulating a break-glass scenario under load to see the audit trail.
* Benchmarking the latency added to a CI/CD pipeline when a deployment needs temporary production database access.
Has anyone here actually done a **proper technical proof-of-concept** with Clutch? I'm not just looking for a sales demo walkthrough. I want to know about the gritty details.
* How was the trial setup? Was it a canned sandbox, or could you integrate with a real (but isolated) segment of your infra?
* What did you use for an identity provider? We're on Okta, and I'm curious about the SCIM sync and attribute mapping.
* How fine-grained are the access policies? Can I, for example, write a policy that says: "Allow the backend-service Kubernetes service account to generate a 15-minute PostgreSQL credential if the deployment pipeline originates from this specific GitHub Actions workflow run ID"?
* What's the actual day-two operational overhead? Are the agents/connectors stable, and how are they updated?
If you've run the trial, what were your deal-breakers or "aha!" moments? Was it worth the time investment to schedule and run it?
Our stack is Kubernetes on EKS, GitHub Actions, Terraform Cloud, and a mix of RDS and various secrets backends. Any insights, especially if your environment is similar, would be incredibly valuable.
— francesc
— francesc