Prove

Access reviews that don’t eat a quarter.

Mid-market teams report spending 40 to 120 hours a quarter on manual access review. Most of it is spent chasing reviewers and reconciling spreadsheets, not deciding anything.

An employee identity, drawn as an ant sealed in amber
Ant — the employee. A colony: ordered, countable, and the population your reviewers will actually be asked about.

The mechanism

Review what changed. Certify the rest by policy.

Teams running this way report cutting review time by 70 to 80 per cent. The saving is not magic — it comes from two decisions.

Delta-only campaigns

A reviewer who is shown four hundred lines certifies four hundred lines without reading them. That is rubber-stamping, and everyone involved knows it.

Amberlock shows what changed since the last campaign: new access, changed entitlements, new joiners, anything that crossed a risk threshold. The list is short enough that reading it is realistic, which is the only way a certification means anything.

Auto-certification for low-risk access

Access that is unchanged, low-risk and consistent with an established pattern certifies itself under a policy you approve, and the policy decision is recorded as the evidence.

The agent proposes; you approve. It drafts candidate policies from what it observes, and no policy takes effect without a human accepting it.

Reviewers

Nobody learns a console.

The reason campaigns stall is not that managers refuse. It is that reviewing means logging into a tool they use four times a year and cannot remember.

Slack Jira ServiceNow Email

Reviewers act where they already are. They get the decision, the context behind it, and two buttons. Amberlock chases the ones who have not answered, escalates the ones who will not, and records every decision as it happens rather than reconstructing it afterwards.

Evidence

One click, mapped to the framework.

SOC 2

Logical access evidence packaged against the Trust Services Criteria your auditor is testing, with the review decisions and their timestamps intact.

ISO 27001

Access control and review evidence mapped to the relevant Annex A controls, exportable as a single package per campaign.

SOX ITGC

Access provisioning, review and segregation-of-duties evidence for the in-scope financial systems, with toxic combinations called out explicitly.

Cyber-insurance questionnaires

The privileged-access and offboarding questions answered from your actual data rather than from memory and optimism.

Works with your compliance platform, not against it.

If you already pay for Vanta or Drata, keep them. They are good at what they do — continuous control monitoring, policy management, audit project management — and none of that is what this is.

The distinction is worth being precise about, because it is where the money is. Drata is review-only by its own documentation. Vanta markets remediation workflows. Both of them track that a review happened. Neither reads the entitlements inside your applications, and neither verifies that revoked access actually disappeared.

Amberlock performs the review and pushes the evidence into the platform you already own. You are not replacing a compliance platform. You are giving it something real to record.

Straight answer

Would attestation alone fail your audit?

No — and anyone who tells you otherwise is selling. Auditors accept attestation evidence today. SOC 2’s Trust Services Criteria are outcome-based and do not mandate access reviews by name. A manager ticking a box in a spreadsheet has been passing audits for twenty years and will keep passing them.

So the argument for verified remediation is not that you will fail without it. The argument is that attestation tells you a review happened, and verification tells you the access is gone. One is a record of process. The other is a statement about the state of your estate.

The breach does not care which one you have. It walks in through the account that was certified as fine.

Find out what is in your amber.

Register for early access. Connect one system read-only, and see your first findings within the hour — the accounts nobody owns, the privilege nobody granted, the access that was never actually removed.

A service account, drawn as a scorpion sealed in amber

Scorpion — the service account. Ancient, over-privileged, still venomous. Real scorpions turn up in real amber, which makes this the most literally accurate specimen in the set.