How a Fortune 50 Company Reduced Its Attack Surface with Continuous Identity
Editor's note: This customer deployed SGNL prior to its acquisition by CrowdStrike. SGNL's continuous authorization and identity orchestration capabilities are now part of CrowdStrike Falcon® Next-Gen Identity Security.
A Fortune 50 company, one of the world’s largest enterprises, operates business-critical cloud infrastructure supporting tens of billions of dollars in annual revenue. Maintaining continuous availability while protecting its production systems from identity-based threats is a strategic priority. This organization chose SGNL to replace static access with real-time, context-aware authorization that grants privileges only when justified by business need.
The adoption of SGNL transformed the company’s approach to secure privileged access. Today, they have replaced approximately 30,000 static AWS role assignments with just six contextual authorization policies that automatically govern privileged access across roughly 500 AWS accounts. These steps dramatically reduced its potential blast radius, saved more than 100 hours each quarter on access certifications, and established a scalable foundation for continuous identity.
The company has significantly reduced the risk of unauthorized access, employee error, and operational disruption while creating a simpler and more scalable approach to identity security.
Eliminating Standing Privilege from Critical Cloud Infrastructure
One of the company's largest business units employed more than 100,000 people and managed customer-facing applications and cloud infrastructure that demanded constant availability. While the organization had invested heavily in enterprise security technologies and employed highly skilled DevOps and infrastructure teams, one challenge remained difficult to solve: standing privileged access to AWS production environments.
Thousands of employees maintained persistent access to critical cloud resources long after legitimate business needs had passed. If a threat actor compromised an identity, or an authorized employee made a mistake, the resulting operational outage or data exposure could have significant financial and reputational consequences.
The rise of identity-driven attacks across the industry reinforced the organization's concern that compromised credentials and excessive standing privilege had become one of the greatest risks to cloud operations. The company's identity security leaders concluded that eliminating standing privilege would be necessary to meaningfully reduce risk.
A Better Approach to Privileged Access
The organization identified AWS as its highest-priority environment for implementing zero standing privilege. Its objective was straightforward: remove persistent AWS access for employees while ensuring authorized personnel could still obtain privileged access quickly during approved production incidents or planned maintenance activities.
Existing privileged access management, identity governance, and administration platforms proved incapable of supporting the dynamic workflows required to accomplish that goal. Even after augmenting those platforms with internally developed identity tools, the organization could not automate access decisions or revoke privileges quickly enough to eliminate standing access.
The company needed an approach that continuously evaluated identity, business, and operational context before granting access — and immediately removed access when that context changed.
It selected SGNL because its continuous authorization capabilities aligned with that vision. Today, those capabilities are part of Falcon Next-Gen Identity Security, enabling organizations to make real-time authorization decisions based on identity, security, and business context.
The company began with a focused proof of concept centered on one critical use case: dynamically granting AWS production access only after verifying business justification through existing identity and IT service management systems. Rather than relying on permanent role assignments, SGNL automatically granted access only after validating approved identity information and change management requirements. When the approved work concluded or business context changed, privileged access was immediately revoked.
Within weeks, the POC successfully demonstrated that zero standing privilege could be implemented without disrupting business operations. Strong feedback from identity, DevOps, and infrastructure teams helped accelerate approval for broader deployment across the organization.
Reduced Risk and Simpler Identity Management
The implementation quickly delivered value. Within approximately one week, the solution ingested the required identity and operational data from the company's existing systems of record and allowed teams to begin enforcing contextual access policies. Following the successful POC, the production deployment was completed over the next six months.
By eliminating standing privilege, the company significantly reduced the likelihood that compromised identities could be used to access production environments. Access now exists only for approved business purposes and only for as long as it is required, substantially limiting opportunities for attackers while reducing the risk of costly operational mistakes.
The project also delivered measurable wins. Quarterly access certification efforts were reduced by more than 100 hours and policy management became substantially easier to administer. Instead of managing thousands of individual role assignments, security teams can define and maintain a small set of business-driven policies that are easier for both technical teams and business stakeholders to understand.
The result is stronger security combined with greater operational efficiency — a combination that was difficult to achieve using traditional identity management approaches.
Building a Foundation for Continuous Identity
With zero standing privilege successfully deployed across its AWS environments, the company is expanding its broader identity security strategy.
Future initiatives include extending dynamic authorization across additional enterprise environments, continuously adapting access decisions based on changing identity and business context, strengthening identity threat detection and response, and further automating privileged session management.
By replacing static access with continuous, context-aware authorization, the organization established a modern identity security model that reduces risk without slowing the business. As these capabilities have become part of Falcon Next-Gen Identity Security, organizations can apply the same continuous identity approach to reduce standing privilege, limit blast radius, and continuously adapt access decisions as risk changes.