Desired state versus actual state
Declared infrastructure-as-code is compared with what the provider actually reports. Every difference becomes a drift finding with the resource, the changed field and the moment it was observed.
Servers, buckets, databases and IAM principals are unowned and unbudgeted until they sit next to people, devices and contracts. Lojycal puts them in the same operational graph — with a desired state, an owner and a cost.
A cloud bill tells you what was spent. It does not tell you which team owns the resource, whether it still matches the code that created it, or whether the identity that can reach it belongs to someone who left in March. Lojycal reconciles infrastructure against the same records that already carry people, assets, contracts and controls, so every resource has an owner, a budget line and an audit trail.
Declared infrastructure-as-code is compared with what the provider actually reports. Every difference becomes a drift finding with the resource, the changed field and the moment it was observed.
Idle compute, detached volumes and orphaned storage are surfaced as candidates for review — with the last activity signal that justifies the call.
Spend is attributed to owner, team and cost centre so cloud cost lands in the same financial picture as licences and hardware, instead of a separate spreadsheet.
Leaver events reach cloud identities. Principals, roles and access keys attached to a departing person are listed as part of the offboarding record rather than discovered a year later.
Long-lived keys and secrets are inventoried with their age and rotation state, so stale credentials are visible before an auditor finds them.
Findings map to the control frameworks already tracked in Lojycal, and every decision — accept, remediate, exempt — is written with actor and timestamp.
AWS, Azure and GCP are connected with read-only credentials. Nothing in your environment is modified by connecting.
Each connection begins in dry-run/mock mode. You see exactly which resources would be inventoried and which findings would be raised before anything is recorded live.
Once dry-run output looks right, the connection promotes to live read. Inventory, drift and cost attribution refresh on a schedule.
Remediation is a decision, not a side effect. Actions are approved, attributed and recorded — never applied silently.
Infrastructure governance is one leg of a longer pipeline. Select a stage to see what enters it, what Lojycal does, and what evidence it writes.
Use the arrow keys to move between stages.
Browser Endpoints
Every drift finding, exemption and remediation decision is recorded with the actor who made it, the reason given and the time it happened. When an auditor asks how a production resource came to differ from its declared state, the answer is a record — not a reconstruction.
We walk your AWS, Azure or GCP footprint through the graph in a live session.