# What are the top-rated CIEM platforms for managing identity access across AWS, Azure, and GCP at the same time?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Hi, cloud security and IAM folks on G2, this one's for you. What are the top-rated CIEM platforms for managing identity access across AWS, Azure, and GCP at the same time, without a permissions change in one cloud causing an outage in another.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">What tends to matter for genuine multi-cloud, least-privilege work:</p><ul>
<li>Coverage across all three major clouds from one console, not bolted-together point tools</li>
<li>Permission changes that don't require guessing at what'll break downstream</li>
<li>Visibility into unused privileges before they become the attack surface</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">A few on G2's<a class="a a--md" elv="true" href="https://www.g2.com/categories/cloud-infrastructure-entitlement-management-ciem"> CIEM</a> list are built around that:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/wiz-wiz/reviews">Wiz</a> (4.7/5, 840+ reviews): connects to every major cloud environment under one CNAPP, consolidating CIEM with the rest of cloud security rather than as a separate tool.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/orca-security/reviews">Orca Security</a> (4.7/5, 310+ reviews): agentless across AWS, Azure, GCP, and more, eliminating the need to deploy and maintain multiple point solutions per cloud.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/sonrai-security/reviews">Sonrai Security</a> (4.5/5, 25+ reviews): its Cloud Permissions Firewall enables one-click least privilege with just-in-time access, specifically built so development work isn't interrupted.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For anyone doing this across three clouds: has a permissions tightening ever actually caused an outage for you, and how did you catch it?</p>

##### Post Metadata
- Posted at: 10 days ago
- Author title: Tech Consultant
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;From what I&#39;ve heard, when tightening permissions does cause an outage, it&#39;s almost always something that was working by accident rather than by design, a service role with broader access than it actually needed, and nobody realized the extra permission was load-bearing until it got revoked. The catch usually comes fast, within minutes as the dependent workflow fails, but by then the damage is already done, which is exactly the argument for visibility into unused privileges beforehand rather than finding out through an incident.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 9 days ago
- Author title: SEO Content Writer





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


