Skip to main content
Kervora Cloud Emblem
Kervora CloudAWS Consultancy
Consulting Process & Governance

Evidence-based, controlled, and transparent.

We believe cloud consulting should be predictable. We define the boundary before touching anything, evaluate using actual configuration evidence, explain findings in plain English, and separate review from implementation.

Consulting Methodology

How Kervora Cloud Works

A disciplined four-stage process that prioritises clarity, evidence, and controlled execution at every step.

01
Step 1

Scope

Understand the environment, objectives and agreed boundaries before access or technical work begins.

Define clear engagement objectives and systems in scope
Agree on non-disruptive, read-only access mechanisms (IAM role / audit policy)
Confirm escalation paths and operational communication channels
Document boundaries so expectations remain strictly defined from day one
02
Step 2

Assess

Review the agreed AWS areas using evidence rather than assumptions.

Perform structured inspection across IAM, networking, compute, storage, and logging
Collect and cross-reference configuration evidence directly from AWS APIs
Examine utilization patterns and identify dormant or unoptimized resources
Ensure zero disruption to running production workloads throughout the review
03
Step 3

Explain

Turn technical findings into prioritised, plain-English recommendations.

Translate raw AWS configurations into understandable operational risks and benefits
Separate urgent security risks from useful medium-term optimizations
Provide clear technical rationale linked directly to observed resource IDs
Walk through findings directly with your engineering and leadership team
04
Step 4

Improve

Where requested, implement approved changes with controlled delivery, validation and evidence.

Formulate a scoped change plan with explicit pre-conditions and rollback steps
Obtain formal client approval before executing any configuration changes
Apply updates systematically with Infrastructure as Code or controlled console changes
Validate all results with recorded evidence and provide handover documentation
Access & Governance Principles

Your AWS environment stays under your control.

Granting third-party access to cloud infrastructure requires absolute confidence in handling, intent, and boundaries. Kervora adheres to strict, transparent operational rules designed to safeguard your environment at all times.

Scope Agreed in Advance

We never perform scans or touch infrastructure outside agreed target accounts and pre-defined architectural boundaries.

Least-Privilege Role Access

Assessments use read-only AWS managed policies (such as SecurityAudit or ViewOnlyAccess) tailored strictly to what is needed.

Temporary, Controlled Access

We recommend cross-account IAM role assumption with external IDs or AWS IAM Identity Center sessions rather than static user accounts.

Zero Root Credential Handling

We will never ask for, accept, or handle root account credentials. Root access is never required for consulting reviews.

No Credential Transmission via Email

We explicitly instruct clients never to send AWS passwords, IAM secret keys, or private SSH keys via email or web forms.

Independent Assessment & Approval

Assessment is strictly separate from implementation. No changes are ever applied to your environment without prior written sign-off.

Validation & Change Evidence

Any approved implementation is validated against recorded test steps and configuration evidence before handover.

Immediate Access Revocation

Once work is delivered, client teams simply revoke or delete the assumed IAM role, leaving zero lingering access.

Tangible Outputs

What you receive from an engagement

Depending on the engagement, Kervora provides concise, actionable documentation structured for both engineering teams and business leadership.

Clear Findings

Understand what was identified without having to interpret raw AWS JSON output or cryptic console logs.

Prioritised Actions

Separate urgent risks from useful operational improvements and longer-term architectural considerations.

Supporting Evidence

Where appropriate, findings reference the specific AWS resource IDs, configuration lines, and metrics observed.

Practical Recommendations

Recommendations clearly explain what could be changed, why it matters, and the operational trade-offs involved.

Defined Next Steps

Use the review as a clear foundation for internal engineering, Kervora implementation, or specialist partner delivery.

Have questions about our process?

Speak directly with Shaun to discuss how an assessment or remediation engagement would work for your specific AWS setup.