Common Fate vs Britive: Which Fits Zero Standing Privilege for Cloud Access?
Choose Britive when enterprise runtime zero standing privilege across multi-cloud, apps, and NHI/AI is the product. Treat Common Fate as the AWS/GCP engineer access-workflow shape that wound down in April 2025.
Standing AdminAccess and long-lived IAM user keys still sit in too many cloud shops between on-call tickets. That is the weekly fire this category claims to close: privilege that exists only for the task, then disappears.
The market for that job split. One lane became cloud-native access workflows for engineers on AWS and GCP: request, approve, time-bound grant, Cedar or Terraform policy, optional bring-your-own-cloud. That was Common Fate’s center before the company wound down operations on 15 April 2025 and donated Granted to fwd:cloudsec. The other lane became enterprise runtime privileged access that mints ephemeral permissions across multi-cloud, SaaS, hybrid, and non-human or AI identities. That is Britive’s center today.
Between these two, Common Fate productized engineer-facing JIT access workflows for AWS/GCP. Britive productizes enterprise zero standing privilege that creates and removes permissions at runtime across a much wider identity and cloud surface. Related reading: non-human identity control planes live under non-human identity tools. More side-by-side pages live under Compare.
| Job | JIT access workflows for AWS/GCP engineers (Cedar/Terraform, on-call grants, optional BYOC). Historical product; company wound down Apr 2025 | Enterprise Unified PAM for zero standing privilege: ephemeral runtime permissions for humans, NHIs, and AI agents across multi-cloud, SaaS, and hybrid |
|---|---|---|
| How a bad day closes | Request a time-bound grant to an AWS account, GCP project, or DB entitlement; approve via policy; access expires | Mint task-scoped permissions at the resource when authorized; revoke automatically when the task ends; audit the runtime trail |
| Operator morning unit | Pending access requests, on-call auto-approvals, and grants that should already have expired | Standing privilege inventory to eliminate, plus checkouts across cloud, SaaS, and non-human identities |
| Deploy | SaaS or Bring-Your-Own-Cloud; Terraform-driven policy and integrations | Cloud-native enforcement layer; agentless / proxyless API-first enforcement |
| License/pricing | Public ladder existed: $1,980/yr minimum; Cloud Basic $3 and Advanced $5 per user/mo (checked 9 Sep 2026 on archived pricing UI). New buys are not a going concern after wind-down | Custom enterprise quote; no public self-serve dollar SKU (checked 9 Sep 2026) |
| Who operates it | Platform / cloud security / EngProd owning AWS and GCP access workflows | IAM / PAM / identity security owning enterprise privileged access including NHI and AI agents |
Recent first-party signal keeps the centers visible. Common Fate’s last clear company update is the April 2025 wind-down and Granted donation. Britive deepened the enterprise runtime story with its AWS Security Hub Extended partnership in February 2026.
That is why standing long-lived keys keep losing the argument. A JIT buy only pays off if it removes those credentials instead of wrapping temporary sessions around the same overprivileged standing accounts.
We reviewed first-party documentation, public pricing pages, product announcements, and live community threads. We did not test the products in paid production environments, so this is not a hands-on benchmark.
Common Fate

Britive

Editions and pricing
Only one of these names is still a sales-led enterprise buy in 2026. Price the live vendor honestly, and treat Common Fate’s published ladder as historical packaging context for the vs query.
| How you buy it now | Company wound down 15 Apr 2025; marketing pages may still render. Granted continues under fwd:cloudsec stewardship. Do not plan a new Common Fate platform rollout | Sales-led Unified PAM / CPAM; also available as a curated partner path through AWS Security Hub Extended |
|---|---|---|
| Public units | Historical list: $1,980 annual minimum; Workflows Basic $2 / Advanced $8 per user/mo; Cloud Basic $3 / Advanced $5; Network, Data Warehouse, and IdP Groups $5 each (checked 9 Sep 2026) | No public self-serve dollar SKU; request tailored pricing (checked 9 Sep 2026) |
| What paid unlocked | Access workflows, AWS/GCP cloud access, DB/network access, data warehouse entitlements, IdP group automation, SaaS or BYOC | Runtime ephemeral permissions across cloud, SaaS, hybrid, and on-prem for humans, NHIs, and AI agents, plus audit and policy controls |
| Buyer friction | Vendor continuity risk after wind-down; migration off Common Fate is the real project | Enterprise scoping across clouds, apps, and identity types; procurement via sales or AWS partner path |
If your shortlist still includes Common Fate because an old RFP or an engineer remembers Granted, separate the OSS CLI from the commercial access platform. Granted can continue as an AWS access helper. The Common Fate authorization platform is not an active product you should renew into.
On-call AWS and GCP access workflows
| Primary signal | Time-bound grants to AWS accounts, GCP projects, and related entitlements with Cedar policy and Terraform config | Runtime authorization that can cover AWS among other clouds, but commercial center is broader ZSP PAM |
|---|---|---|
| Where it shone | Cloud-native teams that wanted Slack/Jira-visible requests, on-call context from PagerDuty or OpsGenie, and BYOC so automation stayed in their account | Enterprises that need the same least-privilege checkout pattern across many clouds and apps, not only AWS/GCP engineer grants |
| Risk close | Grant activates after approval or policy, then expires; audit of request lifecycle | Permissions created at the resource for the task and removed when the task ends |
| What teams argue about | Whether AWS/GCP workflow coverage plus Cedar is enough without a full multi-cloud PAM program | Whether enterprise PAM overhead is justified when the urgent pain is only AWS on-call access |
Common Fate leaned into that Cedar-shaped policy story for human cloud grants. Britive’s answer to the same standing-privilege fear is ephemeral permissions and a wider identity surface, including agents.
Enterprise multi-cloud zero standing privilege
| Primary output | JIT grants and audited sessions primarily around AWS, GCP, and selected data/network entitlements | Zero standing privilege across multi-cloud, SaaS, hybrid, and on-prem for humans, NHIs, and AI agents |
|---|---|---|
| Operator unit | Access requests and grant expiry for engineer production access | Privilege checkouts and standing-privilege elimination across the identity inventory the PAM program owns |
| Weekly loop | Shrink standing AWS/GCP admin roles for humans who only need temporary production access | Shrink standing privilege for people, machines, and agents so compromise has nothing persistent to steal |
| What teams argue about | Whether a wound-down AWS/GCP workflow product still belongs on a 2026 shortlist | Whether “JIT access” language from legacy PAM equals Britive’s ephemeral permission model |
Buy Britive for this pair when the program must cover Azure and SaaS alongside AWS, and when non-human or AI identities are first-class actors. Treat Common Fate as the historical AWS/GCP workflow reference, not the live enterprise ZSP platform.
Where they overlap
Both speak JIT, least privilege, IdP integration, and audit. Both target teams tired of standing cloud admin. Overlap is vocabulary and the desire to kill always-on privilege, not identical product surfaces or vendor continuity. Buying them as interchangeable “JIT cloud PAM” SKUs without the workflow-versus-enterprise-ZSP split mis-scopes the RFP.
When to use both
Practically, you do not run both as commercial platforms in 2026: Common Fate wound down. Some teams still run Granted for AWS role switching while evaluating Britive (or another live ZSP PAM) for enterprise privilege elimination. Keep one owner for which system grants production elevation.
Skip Common Fate for a new buy if you need a supported vendor, multi-cloud coverage beyond AWS/GCP, or NHI/AI runtime privilege. Skip Britive for this pair only if your scope is a narrow AWS engineer access workflow and you are comparing historical product shapes or OSS helpers rather than buying enterprise PAM.
Decide the job first. If the product must deliver enterprise runtime zero standing privilege across cloud, apps, and NHI/AI with an active vendor, that is Britive. If you are naming the AWS/GCP engineer access-workflow shape from this vs query, that was Common Fate, and the company wound down in April 2025. Only then open a sales path or a migration plan.
FAQs
Are Common Fate and Britive the same JIT PAM product?
No. Both talk about just-in-time least privilege, but between these two Common Fate centered on AWS/GCP engineer access workflows (and wound down in April 2025), while Britive centers on enterprise zero standing privilege across multi-cloud, apps, and non-human or AI identities.
Is Common Fate still available to buy?
Common Fate announced it was winding down operations on 15 April 2025. Marketing pages may still load, and Granted continues under fwd:cloudsec, but the commercial access platform is not a going concern for new enterprise rollouts.
Do either publish list prices?
Common Fate published a per-user monthly ladder with a $1,980 annual minimum (checked 9 Sep 2026 on the still-rendered pricing page). Britive does not publish a self-serve dollar SKU (checked 9 Sep 2026).
Is this a scored bake-off?
No. Order is editorial. Prefer Britive for a live enterprise zero standing privilege program.