Hardened 47 IAM roles in 11 days.
Series B fintech needed audit-ready IAM before SOC 2. We refactored every role into least-privilege Terraform modules.
What we walked into.
Three production accounts had accumulated 47 IAM roles over four years of fast hiring. Permissions had crept upward. Wildcard actions on S3, full RDS access for read-only services, and a handful of admin roles assumed daily by engineering. Cross-account trust relationships were undocumented.
SOC 2 Type II audit was 14 days out. The auditor had already flagged IAM as the largest evidence gap. The client had no in-house security engineer; their CTO needed someone who could move fast without breaking production.
How we shipped it.
Inventory
Pulled every role, policy, and trust relationship across the AWS Organization into a single audit table. Categorised by usage (CloudTrail-confirmed) versus declared (IAM-defined). 31% of permissions had not been used in 90 days.
Least-privilege rewrite
Generated proposed policies from CloudTrail Access Advisor data, reviewed each one against service runtime requirements, and rebuilt every role as a Terraform module. Each module is reusable across accounts and version-controlled.
Phased rollout with kill-switch
Deployed tightened policies behind boundary conditions first (so old permissions still worked), monitored CloudTrail for denied actions for 48 hours per role, then removed the boundary. Zero rollbacks needed.
Hand-off and evidence pack
Delivered a runbook for adding new roles, an IAM-changes Slack alert, and a redacted evidence pack the auditor accepted without follow-up.
AWS services in this engagement
What shipped.
Audit closed clean. SOC 2 Type II report issued on time, with the auditor flagging the IAM posture as the strongest control area in the report.
Engineering velocity unaffected. The new modules are simpler to extend than the old hand-written policies. The client has added 12 new roles since hand-off, all on the same pattern.
A companion that remembers.
Merkx is a live AI companion built so that memory is the product and conversation is only the surface. Claude sits at the memory, response, critique, and personality layers that make it feel like a presence.
AIFrom schema to running backend.
Auxen turns a database schema into deployable, production-shaped code across eleven frameworks. Claude drafts the schema, holds the architecture across dozens of files, and explains every decision it makes.
PlatformCut cloud spend 38% in 6 weeks.
Multi-region platform was burning compute. We re-sized the fleet, moved to Graviton, and added a savings plan model that paid back in 21 days.
Tell us what you're trying to ship.
A 30-minute scoping call with the engineers who would do the work.