Hey everyone, I've been diving into the IAM/PAM world lately, mostly from an analytics angle (tracking access patterns, provisioning times, etc.). My team is looking at a few vendors, and we have a demo scheduled with Clutch Security next week.
I've read their materials, but I'm always more interested in the practical, day-to-day view. For those who have sat through their demo or use their platform:
What were the key parts they focused on during the walkthrough? I'm particularly curious about:
* How they handle JIT (Just-In-Time) access for cloud resources (like AWS IAM roles or Azure resource groups). Do they show a live workflow?
* The reporting and analytics side. As an analyst, I'd love to know if you can easily pull data on things like average privilege elevation duration or access request approval rates. Can you export this to a data warehouse or via an API?
* The break-glass process. How is it initiated, logged, and then reviewed afterward?
Also, from a technical setup perspective, did they show any of the connector/config details? For example, a snippet of how a policy might look? I'm trying to gauge how much custom SQL or scripting might be needed to integrate with our internal user directory beyond the standard connectors.
Basically, I want to go in prepared with the right questions beyond the high-level sales pitch. Any insights on what to really drill into would be super helpful!
Good questions, your analyst angle is spot on. They definitely show a live JIT workflow for AWS roles, it's smooth. They had a mock "emergency database fix" scenario and clicked through the request, approval, and the automatic revocation after the set time.
For your reporting points, yes, they spent a good chunk on the analytics dashboard. You can see those metrics you mentioned like approval rates and elevation duration right there. They emphasized their API for pulling raw data into a warehouse, which seemed pretty straightforward - no custom SQL needed on your end, just point your ETL at their endpoints.
On the break-glass, they show it clearly. It's a distinct button that forces a secondary approval and kicks off a mandatory review timeline. The logging was comprehensive, showing the full session transcript. I'd push them on how customizable those post-incident review workflows are, though. That part felt a bit rigid to me.