> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Identity rightsizing

> Review evidence-backed least-privilege recommendations and provider readback.

Identity rightsizing compares current provider grants with complete usage,
attribution, lifetime, and shared-access evidence. Recommendations are
deterministic previews over an immutable grant snapshot; explanatory text does
not decide which permissions to remove.

## Setup

Configure rightsizing from the cloud integration or the rightsizing settings
surface. Each provider requires distinct authorities for inventory and evidence
reads, the bounded mutation, and independent readback.

Guided setup generates provider-native CLI or Terraform artifacts and validates
the exact roles, trust, logging, and evidence sources. A successful inventory
test does not prove rightsizing readiness. Choose an analysis window that your
provider logs and grant history actually cover. Forge does not interpret
missing history as inactivity.

## Recommendation gates

A removable grant is proposed only when Forge can prove the current snapshot
and identity, fresh evidence spanning the configured window, correctly
classified activity, known shared consumers and conditions, an identity-scoped
mutation, and exact readback and rollback plans.

If any gate is incomplete, the provider scope remains coverage-limited and
names the missing evidence. Forge does not manufacture a recommendation from a
healthy connection alone.

## Review and execution

Open a recommendation from an NHI or Agent identity. Review current access,
observed use, the proposed change, evidence coverage, blast radius, shared
access, and expected readback.

Approval records a decision on the immutable preview; it does not mutate the
provider. Before execution, Forge reads provider state again and stops if it no
longer matches the approved snapshot. After provider acceptance, independent
readback is required before Forge reports the change verified.

Residual access, propagation delay, alternate grants, active sessions, and
cached credentials remain visible. Rollback uses the immutable rollback plan
and requires its own readback. For an Agent identity, narrowing creates a new
access-profile revision or moves an assignment; Forge never edits an active
immutable revision in place.
