What this measures
Work that leaves no trace in git.
Someone who spends a week keeping servers alive produces no commits and reads as idle everywhere else in this platform. CloudTrail is the only record that the work happened and who did it.
A CloudTrail write is not a unit of work, so events are weighted rather than counted. Signing in, changing your own password and opening a CloudShell terminal are all writes, and all score zero — presence is not delivery. Creating a load balancer and toggling a notification setting are both one row, and are not worth the same.
Only 90 days exist. No CloudTrail trail is configured on this account, so nothing before 2026-06-29 can ever be recovered. An empty period means “not retained”, never “nothing happened”.
Weighted points
19686
6099 scoring changes
People
13
across 85 days
Concentration
38%
held by Pankaj Kumar
Bus factor
3
people holding 80% of it
Invisible to every other measure
Infrastructure work in this period, and no commits at all.
This is the question the AWS ingest was built to answer. Without it each of these people reads as having delivered nothing.
Ranking
Weighted by what each change did. infra-v1.
| # | Person | Points | Changes | Days | Mix | Services |
|---|---|---|---|---|---|---|
| 1 | Pankaj Kumar | 7391 | 2213 | 54 | Provisioning 705Deployment 237Access & security 376Configuration 89547 unscored | acm amplify cloudformation cloudfront +4 |
| 2 | Harsh Patel | 5742 | 1794 | 38 | Provisioning 474Deployment 210Access & security 312Configuration 79862 unscored | acm amplify autoscaling cloudformation +15 |
| 3 | Abhishek Kulkarni | 2952 | 942 | 44 | Provisioning 191Deployment 133Access & security 229Configuration 389440 unscored | agreement-marketplace amplify apigateway apprunner +21 |
| 4 | Ankur Kumar | 825 | 237 | 26 | Provisioning 91Deployment 2Access & security 74Configuration 7026 unscored | amplify ec2 ec2-instance-connect iam +3 |
| 5 | Anshuman Parmar | 801 | 253 | 17 | Provisioning 42Deployment 6Access & security 157Configuration 48144 unscored | agreement-marketplace amplify autoscaling cloudformation +8 |
| 6 | Rushendra Varma Mudunuru | 790 | 267 | 27 | Provisioning 32Access & security 160Configuration 7562 unscored | access-analyzer bedrock budgets cloudtrail +15 |
| 7 | Dhiraj Ambekar | 671 | 184 | 22 | Provisioning 54Deployment 56Access & security 29Configuration 4537 unscored | amplify autoscaling cloudformation ec2 +6 |
| 8 | Aziz Bohra | 327 | 138 | 10 | Provisioning 17Configuration 12133 unscored | q route53 ses sts |
| 9 | Akash Kumar | 104 | 37 | 7 | Provisioning 5Deployment 6Access & security 3Configuration 2317 unscored | amplify ec2 q route53 +1 |
| 10 | Rushikesh Powar | 45 | 21 | 8 | Provisioning 1Configuration 204 unscored | ec2 route53 s3 |
| 11 | Jitu Prosad Saha | 38 | 13 | 3 | Provisioning 2Deployment 3Configuration 85 unscored | amplify route53 ses |
| 12 | Pranav Ojha | 0 | 0 | 2 | 3 unscored | |
| 13 | MOHD NAVED | 0 | 0 | 1 | 3 unscored |
Access posture
Read off the sign-in events already ingested. Not part of any score.
This says nothing about how well anyone works and feeds no ranking. It is here because CloudTrail records whether a console sign-in used MFA, this platform already reads CloudTrail, and reporting infrastructure work while sitting on evidence that none of it is protected would be a strange kind of silence.
| AWS user | Sign-ins | With MFA | Failed | IPs |
|---|---|---|---|---|
| pankaj | 31 | none | 19 | |
| dhiraj | 27 | none | 26 | |
| Harsh_Patel | 20 | none | 16 | |
| Rushendra_Verma | 14 | none | 9 | |
| ankur@kyma.world | 12 | none | 8 | |
| Akash | 10 | none | 10 | |
| abhishek | 6 | none | 6 | |
| Jitu_Shah | 2 | none | 1 | |
| Aziz-Bohra | 1 | none | 7 | 1 |
| Abhishek_K | 46 | 1 | 3 | 13 |
| Anshuman_P | 22 | 5 | 19 | |
| Harsh-V | 16 | 16 | 6 | |
| Rushendra_V | 13 | 13 | 13 | |
| Aziz-B | 8 | 8 | 1 | 8 |
| Pankaj-S | 8 | 8 | 5 | |
| Dhiraj-A | 4 | 4 | 4 | |
| Ankur | 1 | 1 | 1 |
How a change is weighted
The whole formula.
Brought infrastructure into existence or removed it — stacks, instances, load balancers, databases, apps.
Shipped a change to a running environment — builds, releases, environment rebuilds.
Changed who or what can reach something — security groups, IAM policies, keys, bucket policies.
Tuned infrastructure that already existed — attributes, scaling settings, DNS records.
Signing in, securing your own login, opening a shell. Presence, not delivery — scored at zero.
Where the work happened
AWS services touched, by change count.