Outpost
Use casesHow it worksPoliciesAccessAIIntegrationsPricingFAQ
Google Cloud

Google Cloud

Cloud Infrastructure

Monitor Google Cloud IAM access and offboarding

Continuous visibility into the members, role bindings, service accounts, and projects across your Google Cloud organization — including the privileged access nobody remembered to remove.

Your Google Cloud organization is where your workloads and data actually run, and access to it accumulates faster than anyone reviews it. Engineers get an Editor role on a project for a quick fix, service accounts are minted for pipelines and forgotten, and a primitive Owner binding granted at the org level quietly cascades down to every project beneath it. Each grant made sense at the time. Together they become a privilege surface nobody can describe from memory.

The default Google Cloud experience makes this worse. IAM is inherited across the resource hierarchy, role bindings live per-project, and service accounts are a separate world entirely. To answer a simple question — who can administer this project, and should they? — you'd click through IAM screens project by project and still miss the Owner binding inherited from a folder three levels up.

Outpost replaces that with a single, continuously-synced inventory. It reads your organization through a read-only role — Viewer plus Security Reviewer — and surfaces every member and the roles they hold, every service account and its keys, and the IAM posture of each project. You can finally see your whole org's access in one place and search it like the asset it is.

Catch Google Cloud access that outlives employment

The most dangerous Google Cloud access is the access that should already be gone. An engineer leaves, HR closes their accounts, but their role bindings — and the project access that came with them — quietly survive. Service-account keys are worse still: a key created for an integration isn't tied to any offboarding checklist at all.

Outpost is built around catching exactly this. Because it links each Google Cloud principal back to the person behind it, the moment someone is marked as departed, their lingering role bindings, project access, and any privileged grants surface for review. You don't have to remember that the contractor still has Editor on the production project — Outpost remembers for you.

That's the difference between hoping offboarding was complete and proving it. Outpost turns "who can still reach our Google Cloud?" from a manual audit nobody has time for into a question you can answer continuously.

What Outpost detects

Everything we surface from your Google Cloud workspace.

Members and IAM role bindings

Outpost syncs every principal with a role binding across your organization, folders, and projects — including primitive Owner and Editor roles — so broad, inherited access is finally visible.

Service accounts and keys

Outpost surfaces service accounts, their user-managed keys and key age, and which accounts hold privileged roles, so non-human identities don't become an unmanaged backdoor.

Projects and organization policy

For every project in your organization, Outpost tracks the IAM posture and org-level policy, so misconfigured access can't hide in a project nobody reviews.

Assets we track

Outpost creates and maintains these asset types from your Google Cloud data.

gcp organization
gcp project
gcp service account

How it works

1

Connect

Grant Outpost a read-only role — Viewer plus Security Reviewer — at the organization level. Outpost only ever reads; it never changes IAM, resources, or data.

2

Discover

Outpost inventories your organization, projects, members, role bindings, and service accounts, and creates assets you can search, filter, and review in one place.

3

Monitor

Role bindings, service-account keys, and project posture are re-synced continuously, so new Owner grants and aging keys are tracked over time.

4

Offboard

When an employee leaves, Outpost links their identity to the Google Cloud principals and role bindings they still hold, so lingering project access surfaces instead of sitting unnoticed.

Frequently asked questions

Connect your organization to Outpost and it inventories every principal with an IAM role binding across your org, folders, and projects — including inherited and primitive Owner and Editor roles. Instead of checking IAM project by project, you get one searchable view of who can reach what.

Outpost continuously syncs your members and role bindings and links each to the person behind it. When someone is offboarded, their lingering project access and Owner or Editor bindings are flagged for review, so privileged access doesn't outlive their employment.

Yes. Outpost surfaces service accounts, their user-managed keys with key age, and the roles they hold, so privileged or stale non-human credentials surface for review before they can be exploited.

Outpost

See your entire Google Cloud footprint in one place

Join the waitlist for early access to Outpost's Google Cloud integration and every other tool in your stack.

Explore more integrations