Governance with automation
Secure collaboration without sacrificing velocity. The rules run on every change, so nobody has to remember them.
Policy as code
OPA, Conftest, and Checkov run on every plan, before merge.
- Block non-compliant changes before they reach production
- A failing check opens a named gate
- A human with the right role approves the gate by token, in the pull request
Approvals that follow ownership
Who signs off depends on what changed, not on one repository-wide rule.
- Apply requirements per directory and environment
- Any of the platform team, all of the security team
- Routing from CODEOWNERS, required status checks
Least-privilege access
Terraform state is all-or-nothing. Stategraph scopes every token to capabilities on resources.
- Plan and apply granted separately
- Tenant, state, or resource scope, with wildcards for a module subtree
- Service accounts for CI, with tokens that never exceed their creator
Identity
Sign in through the identity provider you already run.
- OIDC against your identity provider: Okta, Microsoft Entra ID, Auth0, Keycloak. Or Google sign-in
- Restrict sign-in to your email domain
- Every operation tied to who ran it
Audit trail
Every state change is a transaction with an author, a timestamp, and a full record.
- Immutable timeline, point-in-time views
- Query it with SQL, the same data the API exposes
- Pipeline changes read as the pipeline, not a departed employee's key
Blast radius before merge
Know what a change reaches, including resources in other states.
- Computed on the real dependency graph, remote-state consumers included
- Downstream impact shown in the same plan
- A change that would reach outside a token's capabilities is denied, not half-applied
Beyond the pull request
Governance does not stop when the apply finishes.
Cost governance
A current-vs-planned cost delta in the plan, thresholds that require extra approval, attribution by tag and owner, and estimates reconciled against actual spend when a billing source is connected.
Drift detection
Scheduled hourly through monthly, scoped by tag query, inside a maintenance window you set. Opens an issue on detection, or reconciles the drift automatically.
Unmanaged resources
Gap analysis finds cloud resources that exist in your account but are not managed by any Terraform state, so you can bring them under code.
See governance in action
A production security group change. The policy check passes, and the apply waits for the security team.
Governance as configuration
Approval rules and policy steps live in the repository. Access scope lives on the token.
Approvals and policy, per directory
Production needs the platform team. Anything touching IAM needs everyone on the security team. Production plans run Conftest before they are posted.
A credential that does exactly one thing
A CI token that commits to one state cannot manage users, cannot mint more tokens, and cannot touch any other state.
Deploy where compliance requires
The same CLI, API, and features wherever it runs. Postgres encryption at rest, TLS in transit.
Stategraph Cloud
Fully managed. Single-tenant on paid tiers.
Self-hosted
Docker Compose, Kubernetes, Amazon ECS, or Google Cloud Run in your own infrastructure. Fully air-gapped if you need it.
Bring your own cloud
Our engineers operate Stategraph inside your AWS, GCP, or Azure account. You own the data and the account.
Zero-trust execution
The CLI runs Terraform where you run it, with your credentials. The server stores state and never sees your cloud.
Need SSO, RBAC, data residency, or a custom SLA? See Enterprise → · Security overview →
Ready to implement infrastructure governance?
Start enforcing policies and standards on every change, automatically.