Skip to main content
Identity rightsizing compares current provider grants with complete usage, attribution, lifetime, and shared-access evidence. Recommendations are deterministic previews over an immutable grant snapshot; explanatory text does not decide which permissions to remove.

Setup

Configure rightsizing from the cloud integration or the rightsizing settings surface. Each provider requires distinct authorities for inventory and evidence reads, the bounded mutation, and independent readback. Guided setup generates provider-native CLI or Terraform artifacts and validates the exact roles, trust, logging, and evidence sources. A successful inventory test does not prove rightsizing readiness. Choose an analysis window that your provider logs and grant history actually cover. Forge does not interpret missing history as inactivity.

Recommendation gates

A removable grant is proposed only when Forge can prove the current snapshot and identity, fresh evidence spanning the configured window, correctly classified activity, known shared consumers and conditions, an identity-scoped mutation, and exact readback and rollback plans. If any gate is incomplete, the provider scope remains coverage-limited and names the missing evidence. Forge does not manufacture a recommendation from a healthy connection alone.

Review and execution

Open a recommendation from an NHI or Agent identity. Review current access, observed use, the proposed change, evidence coverage, blast radius, shared access, and expected readback. Approval records a decision on the immutable preview; it does not mutate the provider. Before execution, Forge reads provider state again and stops if it no longer matches the approved snapshot. After provider acceptance, independent readback is required before Forge reports the change verified. Residual access, propagation delay, alternate grants, active sessions, and cached credentials remain visible. Rollback uses the immutable rollback plan and requires its own readback. For an Agent identity, narrowing creates a new access-profile revision or moves an assignment; Forge never edits an active immutable revision in place.