Access management
Temporary Elevated Access Management (AWS TEAM)
Just-in-time, time-bound admin access across AWS accounts, with Okta identity, approval workflows, MFA and full session auditing.
- AWS TEAM
- IAM Identity Center
- Okta
- CloudTrail
- CloudWatch
The problem
Standing admin access is convenient and risky. The aim was to make elevated access temporary by default: requested, approved, time-limited, revoked automatically, and fully audited.
What I built
- Okta integrated with AWS IAM Identity Center, with Okta handling user provisioning and MFA.
- Granular permission sets across accounts, so elevated roles are scoped to the job instead of one “admin” role for everything.
- An automated request → approve → revoke workflow for time-bound elevated access.
- Session auditing with CloudTrail and CloudWatch for security monitoring and compliance.
Stack
AWS TEAM · IAM Identity Center · Okta · CloudTrail · CloudWatch