Skip to main content
Least privilege, by default

Access scoped
to each
resource.

Three built-in roles, custom roles scoped down to individual resources, and team access that follows the resources a team owns. Bring your cloud's own access model with you rather than rebuilding it by hand.

Free to start. No card. The playground just needs your work email.

3built-in roles, plus custom
Per resourcescoping for any role
0admin rights copied from cloud IAM
SAMLsingle sign-on

AWSGoogle CloudAzure

Access that follows ownership.

Scope follows the team, not a spreadsheet.

01

Start from a role

Admin, Editor or Viewer cover most people. Editors change resources; only Admins manage the account itself.

02

Scope it down

Custom roles narrow any permission to named resources. A contractor can manage the schedules for one set of named resources and see nothing else.

03

Let teams inherit

Team members get their role's permissions, scoped to the resources the team owns.

04

Cloud IAM Import

Pull IAM principals from AWS, Google Cloud and Azure as suggested users, teams and roles. Nothing is written until you review the preview and click Apply.

Least privilege, without the spreadsheet.

Enforced in one place, for people and agents alike.

Enforcement
Every API call is checked at the gateway against the permission it needs. There is no way around it, including for AI agents over MCP.
Scoping
Each permission can cover all resources, none, or a named list. Every service filters its data to that scope before returning anything.
Cloud IAM Import
Suggestions only. Admin rights are never granted automatically, even from AWS AdministratorAccess, Google Cloud Owner or Azure Owner, and it never writes to your cloud IAM.
Sign-in
Google, GitHub or email, and SAML single sign-on, set up with the ZopNight team for your email domain.

Give everyone access. Exactly enough.

Invite your team and scope each person in a few clicks, or start from your cloud's IAM.

Prefer to talk it through first? Book 20 minutes with the team.

  • $30M+annualised cloud spend under management
  • 550K+resources tracked since launch
  • 20-60%off the bill in the first month
  • SOC 2Type II report, plus ISO 27001

Figures published on zop.dev.

Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·