Key capabilities
- Normalize create, update, delete, replace, read and no-op actions
- Flag public networks, wildcard IAM, disabled encryption and unprotected secrets
- Enforce explicit total-change, deletion and replacement budgets
- Compare action totals, findings and resource-type shifts with a baseline
