ciem-engineer

Analyze IAM configurations across AWS, Azure, GCP, and OCI for excessive permissions.

Updated Feb 22, 2026
One-click install
npx skills add https://github.com/Muath2000/TradeStation --skill ciem-engineer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ciem-engineer
Source: https://github.com/Muath2000/TradeStation/tree/main/.claude/skills/ciem-engineer
Command: npx skills add https://github.com/Muath2000/TradeStation --skill ciem-engineer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill addresses the complex challenge of managing cloud identities and their permissions across multiple cloud providers, ensuring adherence to least-privilege principles and identifying security risks.

Core Features & Use Cases

  • Cross-Cloud Identity Management: Consolidates and analyzes users, roles, and service accounts across AWS, Azure, GCP, and OCI.
  • Least-Privilege Enforcement: Detects excessive permissions and recommends policy tightening.
  • Risk Assessment: Assigns risk scores to identities based on their privileges, activity, and configuration.
  • Use Case: A security team can use this Skill to identify all administrative roles across their AWS and Azure environments, flag any that haven't been used in 90 days, and receive recommendations for reducing their scope to mitigate potential security breaches.

Quick Start

Use the ciem-engineer skill to analyze excessive permissions for the AWS identity 'arn:aws:iam::123456789012:user/test-user' in tenant 'abc-123'.

Frequently Asked Questions about ciem-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enforce least-privilege across AWS, Azure, GCP, and OCI identities?

To enforce least-privilege across AWS, Azure, GCP, and OCI, analyze IAM configurations to detect excessive permissions and receive policy tightening recommendations. This consolidates identity management across multiple cloud providers.

What is cloud identity risk scoring and how does it identify dormant accounts?

Cloud identity risk scoring evaluates privileges, activity, and configuration to assign risk scores to identities. This process flags dormant or risky accounts, such as administrative roles unused for 90 days, to mitigate security breaches.

How do I analyze excessive permissions for a specific AWS identity?

To analyze excessive permissions for an AWS identity, provide the identity ARN and tenant ID to initiate IAM configuration analysis. This identifies excessive permissions and generates recommendations for reducing the identity's scope.

Can I integrate cloud IAM analysis with enterprise GRC platforms for governance?

Yes, cloud IAM analysis integrates with enterprise GRC platforms for identity governance and risk scoring. This integration manages cloud identity and entitlement posture across AWS, Azure, GCP, and OCI environments.

Does this approach work for managing entitlement postures across multiple cloud providers?

Yes, this approach manages cloud identity and entitlement postures across AWS, Azure, GCP, and OCI. It consolidates users, roles, and service accounts to enforce least-privilege and identify security risks.