Orca Admin Access Grouping

Admin access grouping - fetches Orca's pre-computed admin clustering (IAM Policy Optimizer) for AWS, Azure, and GCP, groups every admin identity into a small number of shared least-privilege policies that replace blanket AdministratorAccess / Owner, and drives the swap through a staged, confirmation-gated apply. Use when the user wants to group or tier their admins, cut down how many people hold full admin, replace AdministratorAccess with role-based policies, or see how few policies their admin population actually needs. Scoped to grouping the admin population org-wide into shared policies - it takes no account, business unit, or tag as scope. Right-sizing individual identities within an account, business unit, or tag belongs to orca-overprivileged-identities-rightsizing; a single named identity's permission review belongs to orca-identity-review.

orcasecurity Updated

File contents

orcasecurity/orca-skills/tree/main/skills/orca-admin-access-grouping commit c70ef71f4a

Frequently asked questions

npx skillmds@latest add orcasecurity/orca-admin-access-grouping