
Invisory contains 3 former-insider access events on AWS, app back same week
During an active former-insider access incident, VeUP delivered AWS-native incident response for Invisory, a B2B SaaS platform — cross-app access revocation, AWS CloudTrail audit forensics, identity-tenant separation, and MFA-gated federation. Three access events contained, the app restored in week one.
The challenge
During onboarding, Invisory faced an active incident in which a former insider retained access across connected applications. The production application was taken offline, legitimate internal users had been deleted, and overlapping identity paths through a single shared production/staging tenant allowed access to be regained — requiring immediate containment, recovery, and durable identity hardening against recurrence.
The solution
AWS-native incident response delivered from day one of onboarding. VeUP revoked access across every connected application against a verified leaver list; ran AWS CloudTrail audit-log forensics and confirmed logging coverage across the AWS account; recreated legitimately deleted internal users and restored the offline application; separated the identity environment from one shared production/staging tenant into isolated production and staging tenants to eliminate the overlapping paths; and re-established MFA-enforced federated access (AWS IAM Identity Center / federation) as the durable control. Production compute runs on Amazon EC2 across multiple regions, with AWS IAM, Amazon SNS, and cost allocation in support.
Production outcomes
| KPI | Result |
|---|---|
| Production outcomes | Three separate former-insider access events were contained over the engagement — the initial takedown, an admin/staging push-path recurrence, and a staging-tenant compromise. The offline production application came back within the first week of onboarding, with legitimate users recreated. The identity environment moved from one shared production/staging tenant to isolated production and staging tenants, AWS CloudTrail coverage was confirmed, and MFA-gated federated access returned as the durable control. |
| Engagement window | Incident response began on day one of onboarding in May 2025. A recurrence in mid-June was contained, and the staging-tenant separation completed in early July 2025. |
| Cost / TCO posture | Not a cost-optimization engagement — value is containment, same-week recovery, and durable identity hardening. AWS Cost Allocation was used in support; no realized-savings claim. |
| Lessons & continuation | Overlapping production/staging identity paths are how revoked access gets regained — tenant separation is the durable fix, not just re-revocation; revoke against a verified leaver list across every connected application; confirm CloudTrail coverage and re-establish MFA-gated federation as the standing control. |
Architecture
The engagement in one picture: the compromised, single shared production/staging identity tenant on one side, the remediated AWS target state on the other — isolated production and staging tenants, MFA-gated AWS IAM Identity Center federation, a cross-application access-revocation boundary, and AWS CloudTrail forensics.

