A veterinary service provider used Native to enforce least privilege through AWS-native controls across 100+ locations, blocking hundreds of destructive actions and cutting its attack surface by more than 70% with no workload disruption.
The veterinary service provider runs 24-hour emergency pet care across more than 100 locations, handling billing and patient information across its national footprint, which carries real regulatory and operational risk. A small security and platform team owned cloud security alongside many unrelated responsibilities, which pushed them into reacting to issues one at a time instead of reducing attack surface and setting safe baselines for new service adoption.
The veterinary service provider expresses its least-privilege requirements as plain-language intent, and Native compiles them into AWS-native controls (SCPs and RCPs) across the organization: blocking usage of unused AWS services to reduce attack surface, and requiring security reviews for new services so applications leverage secure-by-design controls. Native reads real usage patterns from CloudTrail (combined with Resource Manager and Billing API activity) to simulate every policy against historical activity before enforcing, so no identity that legitimately needs access is caught by surprise. Enforcement runs through AWS Organizations with a managed rollout that follows the org tree from test to staging to production, and CloudWatch, CloudTrail, and SNS close the loop by showing both security teams and developers exactly which actions a policy blocked and why.
- reduction in attack surface by restricting cloud usage to approved services and regions
- 70%+
- of attempts to create resources in unapproved locations or perform destructive actions were prevented outright
- Hundreds
INDUSTRY: Veterinary emergency healthcare
REGION: United States (100+ locations)
NATIVE PLATFORM: Organization Intelligence, Intent Translation, Impact Simulation, Integrated Enforcement Feedback, Exception Management
USE CASES: Built-In Prevention, Secure cloud services adoption, least privilege enforcement, AI guardrails
CLOUD PLATFORM: AWS
AWS SERVICES: AWS Organizations (SCPs, RCPs), IAM, CloudTrail, CloudWatch, SNS
Lessons Learned
Simulating against real historical CloudTrail activity before enforcing avoided surprising any identity that legitimately needed access. Rolling out along the organizational tree (test to staging to production) with full visibility into every blocked action and a clean exception path is what gave a stretched team the confidence to enforce in production.