Use case

Infrastructure Governance and Security

Policy checks and approvals in the pull request. Least-privilege access down to a single resource. An audit trail that is the same data as your state, not a separate log nobody reads.

Policy Gates Ownership-Based Approvals Least-Privilege Tokens Immutable Audit Trail SSO
Book a Demo See governance in action

Governance with automation

Secure collaboration without sacrificing velocity. The rules run on every change, so nobody has to remember them.

Policy as code

OPA, Conftest, and Checkov run on every plan, before merge.

  • Block non-compliant changes before they reach production
  • A failing check opens a named gate
  • A human with the right role approves the gate by token, in the pull request

Approvals that follow ownership

Who signs off depends on what changed, not on one repository-wide rule.

  • Apply requirements per directory and environment
  • Any of the platform team, all of the security team
  • Routing from CODEOWNERS, required status checks

Least-privilege access

Terraform state is all-or-nothing. Stategraph scopes every token to capabilities on resources.

  • Plan and apply granted separately
  • Tenant, state, or resource scope, with wildcards for a module subtree
  • Service accounts for CI, with tokens that never exceed their creator

Identity

Sign in through the identity provider you already run.

  • OIDC against your identity provider: Okta, Microsoft Entra ID, Auth0, Keycloak. Or Google sign-in
  • Restrict sign-in to your email domain
  • Every operation tied to who ran it

Audit trail

Every state change is a transaction with an author, a timestamp, and a full record.

  • Immutable timeline, point-in-time views
  • Query it with SQL, the same data the API exposes
  • Pipeline changes read as the pipeline, not a departed employee's key

Blast radius before merge

Know what a change reaches, including resources in other states.

  • Computed on the real dependency graph, remote-state consumers included
  • Downstream impact shown in the same plan
  • A change that would reach outside a token's capabilities is denied, not half-applied

Beyond the pull request

Governance does not stop when the apply finishes.

Cost governance

A current-vs-planned cost delta in the plan, thresholds that require extra approval, attribution by tag and owner, and estimates reconciled against actual spend when a billing source is connected.

Drift detection

Scheduled hourly through monthly, scoped by tag query, inside a maintenance window you set. Opens an issue on detection, or reconciles the drift automatically.

Unmanaged resources

Gap analysis finds cloud resources that exist in your account but are not managed by any Terraform state, so you can bring them under code.

See governance in action

A production security group change. The policy check passes, and the apply waits for the security team.

● Update production security group rules #89 open
S stategraph-bot commented
Stategraph Plan Output
~ aws_security_group.prod_db + aws_security_group_rule.prod_db_ingress_app Plan: 1 to add, 1 to change, 0 to destroy Downstream: 3 consumers in production/app read this group
Policy checks
Checkov✓ passed
Conftest, production policies✓ passed
Approval requirements
Platform team✓ 2/2 approved
Security team⏳ 0/1 required
Production changes require security team approval.
S security-lead approved these changes
Ingress is scoped to the app subnet. Approved.
S stategraph-bot commented after merge
Apply complete
Resources: 1 added, 1 changed, 0 destroyed Transaction recorded: author infra-admin, approvals platform 2/2, security 1/1

Governance as configuration

Approval rules and policy steps live in the repository. Access scope lives on the token.

Approvals and policy, per directory

Production needs the platform team. Anything touching IAM needs everyone on the security team. Production plans run Conftest before they are posted.

# .terrateam/config.yml apply_requirements: checks: - tag_query: "dir:environments/production/**" approved: enabled: true any_of: ["team:platform"] - tag_query: "iam in dir" approved: enabled: true all_of: ["team:security"] workflows: - tag_query: "dir:environments/production/**" plan: - type: init - type: plan - type: conftest

A credential that does exactly one thing

A CI token that commits to one state cannot manage users, cannot mint more tokens, and cannot touch any other state.

# an apply-only token, scoped to one state $ stategraph user access-tokens create \ --name ci-prod-apply \ --apply \ --apply-state '<state-id>=*' # confirm what it can do $ stategraph user whoami

Deploy where compliance requires

The same CLI, API, and features wherever it runs. Postgres encryption at rest, TLS in transit.

Stategraph Cloud

Fully managed. Single-tenant on paid tiers.

Self-hosted

Docker Compose, Kubernetes, Amazon ECS, or Google Cloud Run in your own infrastructure. Fully air-gapped if you need it.

Bring your own cloud

Our engineers operate Stategraph inside your AWS, GCP, or Azure account. You own the data and the account.

Zero-trust execution

The CLI runs Terraform where you run it, with your credentials. The server stores state and never sees your cloud.

Need SSO, RBAC, data residency, or a custom SLA? See Enterprise →  ·  Security overview →

Ready to implement infrastructure governance?

Start enforcing policies and standards on every change, automatically.

Book a Demo Explore Orchestration