"Best Solution for identity and data governance."
Its ability to simplify cloud security by focusing on identity and data governance. It helps uncover over-permissioned accounts, data risks, and misconfigurations across AWS, Azure, and GCP. The solution is very easy to use and implementation was also quick. Customer service support is really good. Integrations are quite confusing as there's no visibility for third-party solutions. Sonrai Security solves problems like too many unnecessary permissions, risky data access, and cloud misconfigurations. It helps you see who has access to what, find sensitive data at risk, and fix important issues first. This makes your cloud more secure, saves time, and ensures everything is compliant.
"Least privilege in days rather than months"
Sonrai saved us months of manual effort to achieve least privilege with its ChatOps permissions firewall enabler and automated SCP management, which had been a pain point for years. If we ever leave Sonrai, we'll have to do all that work manually. It covers cloud identity and access management, least privilege, SCP and RCP automation, and just-in-time access.
"Exceptional Cloud Identity & Data Governance Platform"
Sonrai Security gave us unmatched visibility and control over identity governance and cloud permissions. The platform provides deep insights into identity access paths, risky entitlements, and over-permissioned accounts across multi-cloud environments. The user interface is clean and easy to navigate, making complex security data more actionable. The Cloud Permissions Firewall is particularly impressive—it helps enforce least privilege policies with minimal friction. Sonrai Security helps us identify and eliminate excessive permissions and risky identity access paths across AWS, Azure, and GCP. This has drastically improved our security posture, enabled compliance with internal policies, and reduced the chances of data exposure. The platform also ensures continuous monitoring and provides actionable insights, which streamline our audits and remediation efforts.
"A fix for untamed privileges in AWS"
Sonrai's analytics, policies, and quarantine workflows let us lock down excessive permissions in a controlled, risk-aware way. It's different from our other visibility tools because it provides enforcement. The ability to target unused or risky privileges and act instantly is a huge leap forward for cloud IAM. There's a learning curve if you want to go deep on advanced configuration, but Sonrai's team supports you well through onboarding. We needed a way to implement least privilege, remove unused permissions, and secure high-risk identities in AWS. Sonrai replaces what AWS and traditional PAM tools can't do. We now have automated control over everything from human users to machine identities to third-party access. It's real cloud PAM—not a bolt-on or siloed tool. It helps our team address identity risks in AWS at scale without slowing down developers. It's fast, clean, and flexible.
"AWS IAM Controls made Easy"
The overall workflow was amazing from start to finish when protecting services and identities; it made sense what, how, and when things were happening. Setup was clear and well thought out, allowing full top-to-bottom protection in a few hours. Customer service was always top notch, quickly evaluating issues with a Zoom call within a quick SLA. The UI was a bit tricky to navigate—when mass updating settings, it would reset or clear filters and reload the screen constantly. Future versions can easily fix that. Deploying changes took a long time; I had to iterate the whole stack rather than just the one item I was updating, but I believe that was already on a release branch. From my perspective, it was controlling identity with one pane of glass—roles, users, and policies all controlled for all AWS accounts. Made changes and updates simple, easy to lock down a service or account quickly and effectively, with the ability to revert just as easily.
"Cloud PAM That Actually Works"
Sonrai's Cloud Permissions Firewall delivered the speed and simplicity we wanted—along with real, immediate results. Deployment was quick, and within minutes it was automatically cleaning up thousands of unused privileges across our AWS environment. The interface is user-friendly, the controls are powerful, and it's easy to navigate and master. We particularly value how fast it is to get started and how it simplifies securing our environment without manual effort. It's the first PAM solution we've found that truly matches the speed and agility cloud teams require. There were a couple of minor display bugs in early testing, but the Sonrai team responded rapidly and delivered fixes. They've been transparent and proactive in resolving edge cases. Our biggest challenge was managing privileged human access—users could access resources and permissions we couldn't fully see or control. Sonrai's Cloud Permissions Firewall addressed this by removing unused privileges and replacing always-on access with just-in-time access. Now, access is granted only when needed and after proper approval. As a result, our attack surface has been significantly reduced by eliminating unnecessary privileges and identities. We also appreciate Sonrai's flexibility—it can be deployed broadly or targeted precisely, thanks to granular controls and customizable enforcement. Teams integration makes it easy for users and approvers to manage access in real time, while detailed session summaries give us visibility into activities we previously missed.
"A significant breakthrough in fixing privileges in the cloud."
Sonrai's Cloud Permissions Firewall is built specifically for cloud environments, avoiding the shortcomings of legacy access management tools adapted for cloud use. It offers low-latency performance with minimal deployment overhead and enables rapid just-in-time provisioning for high-sensitivity roles. The only challenge we faced was aligning initial permission mappings within AWS Identity Center. Fortunately, the support team was highly responsive and quickly provided clear guidance. Standing privileges, stale admin roles, and zombie accounts have always been problematic, but these common issues were eliminated with Sonrai's PAM approach. Access is now governed by policy-based controls, with approvals integrated directly into Microsoft Teams, our existing collaboration platform. This lets us maintain agility without sacrificing auditability, control, or visibility.
"Streamlined and Sophisticated Cloud Privileged Access Management"
Sonrai offered an exceptionally smooth experience for implementing just-in-time access governance across our cloud. Deployment was remarkably straightforward—operational in minutes—with effortless Slack integration enabling real-time access orchestration. The platform's elegant architecture combines performance with intuitive design, and automated approvals work with impressive precision and reliability. My only suggestion is to increase transparency around automated approval workflows, especially when roles are shared among multiple users. That's a minor point, and the support team was exceptionally responsive with comprehensive guidance. Our organization struggled with excessive persistent access privileges that created security vulnerabilities. Sonrai's Cloud Permissions Firewall let us systematically remove dormant permissions and shift from static access to dynamic, approval-driven provisioning with intelligent expiration. This transformation significantly reduced risk exposure while improving governance and operational visibility.
"IAM made simple"
I found Sonrai at AWS re:inforce 2024 and had a full POC running in AWS within 15 minutes—nothing flashy, just smooth and effective. From the start, it filled a critical gap in our access protections. Key highlights: effortless least privilege via the cloud permissions firewall—one click quarantines zombie roles, disables unused services and regions, and tightens permissions across the cloud without breaking anything. Third-party tracking and management is a breeze: a single screen shows every ISV with access, lets me see if they follow best practices, and disable them in one click. I can even block unapproved new access by setting the default action to deny. Permissions-on-demand is super simple: a ChatOps workflow that grants only what's needed, only when needed, with no standing permissions, no Jira tickets, and a clear audit trail sent directly to approvers. Just-in-time access with AI-powered summaries takes it to the next level—temporary elevated access is policy-enforced and fully auditable, and integration with Amazon Bedrock gives each session a concise, human-readable summary, perfect for regulated industries. G2 users echo my experience: Sonrai provides unparalleled visibility and control, and it's easy to use with quick implementation. In short, I love how Sonrai simplifies complex security challenges (and that I never have to write another SCP!). It's powerful and intelligent but never heavy. It just works. Nothing. The product is fantastic and fills a unique gap, and the team is dedicated and responsive, turning our feedback into features quickly. Sonrai took what would have been an extremely complex challenge for my small team to even observe access controls in our AWS org and gave me an easy way to fix issues. Without it, I couldn't have solved this without significantly more headcount and probably a year of effort. Instead, I scoped AWS services and regions, quarantined zombie roles, identified and cleaned up overly permissive roles, and managed third-party ISV access with a few clicks. It's that powerful, while allowing me to scope at Org, OU, and Account levels. Achieving just the cleanup would have been monumental or insurmountable, but I've not only solved that, I now have ongoing protection without worrying about writing SCPs and risking production.
"Great Cloud Visibility, Some Learning Required"
Sonrai's identity graph visualization is excellent, clearly mapping out complex access relationships and surfacing hidden risks. It offers full visibility into permissions and risks across cloud environments, automating least-privilege enforcement and remediation which cuts down manual work. I also value that it handles both identities and sensitive data, providing a complete governance solution. However, the initial setup is complex and there's a steep learning curve. The UI can feel overwhelming for newcomers, and alert noise needs adjustment. Deep DevOps pipeline integration is limited, and pricing may be steep for smaller teams. I rely on Sonrai for managing and securing identities across clouds, fixing over-permissions, detecting risks, and automating governance. It gives me visibility and control through the identity graph and automates least-privilege enforcement, reducing manual effort and protecting sensitive data.