Governed cloud execution

Control who can request, review and change cloud infrastructure.

IntelliconOps places role-based permissions, provider and group boundaries, configurable approval gates and saved-plan controls around operations across AWS, Microsoft Azure and Google Cloud.

Book a demonstration

Control path

Permission
Can this user request or operate the resource?
Scope
Which group and cloud boundary applies?
Review
Which workflow, inputs or exact plan will run?
Approval
Does this user have permission to approve the risk?
Execution
Run only the accepted workflow or saved plan.

Scoped requests

Governance begins before the build is submitted.

For a Blueprint request, the selected VM group supplies the operational boundary, including its cloud account, provider placement and approval path.

  • Only accessible groups are available to the requester
  • The published blueprint constrains the available inputs
  • Provider-specific regions, networks and resource choices remain explicit
  • Group owners are notified when member approval is required

Governed OpenTofu lifecycle

Approval is attached to one plan—not a general instruction to make changes.

IntelliconOps binds the proposed actions, configuration identity, reviewer and validity window into a controlled path from validation to apply.

1

Configure

Choose an approved module, cloud account and allow-listed values.

2

Plan

Validate the configuration and save the exact proposed additions, changes, replacements or removals.

3

Authorise

Check the plan identity and expiry. Apply permission is required; destructive work also requires destroy permission.

4

Apply

Lock the deployment and apply the approved encrypted saved plan without regenerating it.

Plan identity

Plan and configuration hashes bind approval to the reviewed proposal.

Time-limited review

Expired plans cannot be approved; a fresh plan is required.

Destructive permission

Destroy or replacement actions require explicit additional authority.

Audit evidence

Validation, planning, approval, rejection, apply and inventory synchronisation are recorded.

Three connected controls

Permissions decide what a person can do. Scope decides where.

Role-based permissions

Roles contain granular permissions for requesting, viewing, approving and operating infrastructure.

RBAC and VM group scope

Membership limits visibility and connects people to the teams, resources and cloud context they are responsible for.

Approval gates

Where the configured path requires review, the job remains pending until an authorised owner or approver makes a decision.

Approved execution

Only accepted Blueprint requests or authorised OpenTofu saved plans proceed to the worker, with their identity and decision retained as context.

Clear responsibilities

Give each participant the access their work requires.

Requester

Selects an available blueprint, supplies permitted values and tracks the resulting request.

Group owner

Manages the group boundary and reviews member requests when approval is required.

Approver

Uses the relevant job or IaC permission to accept or reject controlled work. Permissions can be assigned to match your operating model.

Administrator

Manages roles, granular IaC permissions, cloud accounts and platform-wide configuration.

Control without hidden authority

Put the right decision at the right boundary.

Combine reusable Blueprints, controlled OpenTofu plans, scoped access and granular permissions so routine delivery remains efficient, reviewable and accountable.

Explore platform security

See IntelliconOps in action

Give every cloud request a clear, controlled path.

Tell us how your teams manage infrastructure today. We will show you how IntelliconOps can simplify the work.

Book a demonstration