Drive least privilege, automatically.
Policy Optimizer finds the unused, duplicate, and shadowed rules hiding in your policy and turns recertification from an annual scramble into a continuous program.
Firewall policy only grows — until no one trusts it.
Every change adds a rule; almost none are ever removed. Over years, policy bloats with rules no one can attribute, duplicates, and shadowed entries that quietly widen access. The risk is real and the cleanup is daunting. Policy Optimizer makes it tractable — surfacing exactly what to retire and proving it's safe.
What it does.
The building blocks of the module — each one searchable, evidenced, and inside your perimeter.
Unused-rule detection
Correlate rules against real traffic to find what hasn't matched in months.
Duplicate & shadow analysis
Identify redundant and shadowed rules that add risk without adding function.
Over-permission scoring
Flag overly broad rules — any-any, wide ranges — and suggest tighter, least-privilege equivalents.
Recertification campaigns
Route rules to their owners for periodic review, with a full sign-off record.
Safe-change suggestions
Recommend removals and tightenings with the evidence to approve them confidently.
Cleanup tracking
Measure rule-base reduction and least-privilege progress over time.
From connected to in control.
Baseline the rule base
OpClerk inventories every rule and correlates it with observed traffic and usage.
Surface what to fix
Unused, duplicate, shadowed, and over-permissive rules are scored and queued for review.
Recertify and retire
Owners review and approve; OpClerk records every decision as audit evidence.
What control looks like, measured.
Illustrative targets based on typical engagements — replace with your own figures in the CMS.
Questions teams ask.
It correlates each rule against observed traffic over a configurable window; rules with no matches are flagged for review — never auto-deleted.
No. Optimizer recommends; your team approves. Every change keeps an owner and an approval record.
Yes — periodic recertification with documented sign-off maps to the access-review expectations in frameworks like SAMA CSF and ISO 27001.
See Policy Optimizer on your own policy.
A 30-minute walkthrough on a sample of your own firewall policy — inside your perimeter, nothing leaves.