What this measures
Work that leaves no trace in git.
Someone who spends a week keeping servers alive produces no commits and reads as idle everywhere else in this platform. CloudTrail is the only record that the work happened and who did it.
A CloudTrail write is not a unit of work, so events are weighted rather than counted. Signing in, changing your own password and opening a CloudShell terminal are all writes, and all score zero — presence is not delivery. Creating a load balancer and toggling a notification setting are both one row, and are not worth the same.
Only 90 days exist. No CloudTrail trail is configured on this account, so nothing before 2026-07-02 can ever be recovered. An empty period means “not retained”, never “nothing happened”.
Weighted points
20374
6290 scoring changes
People
13
across 85 days
Concentration
36%
held by Pankaj Kumar
Bus factor
3
people holding 80% of it
Invisible to every other measure
Infrastructure work in this period, and no commits at all.
This is the question the AWS ingest was built to answer. Without it each of these people reads as having delivered nothing.
Ranking
Weighted by what each change did. infra-v1.
| # | Person | Points | Changes | Days | Mix | Services |
|---|---|---|---|---|---|---|
| 1 | Pankaj Kumar | 7375 | 2205 | 55 | Provisioning 707Deployment 237Access & security 370Configuration 89145 unscored | acm amplify cloudformation cloudfront +4 |
| 2 | Harsh Patel | 6347 | 1960 | 37 | Provisioning 537Deployment 213Access & security 390Configuration 82063 unscored | acm amplify autoscaling cloudformation +15 |
| 3 | Abhishek Kulkarni | 2926 | 934 | 41 | Provisioning 189Deployment 132Access & security 227Configuration 386437 unscored | agreement-marketplace amplify apigateway apprunner +20 |
| 4 | Anshuman Parmar | 886 | 281 | 19 | Provisioning 49Deployment 10Access & security 157Configuration 65142 unscored | agreement-marketplace amplify autoscaling cloudformation +9 |
| 5 | Ankur Kumar | 843 | 243 | 28 | Provisioning 91Deployment 2Access & security 80Configuration 7028 unscored | amplify ec2 ec2-instance-connect iam +3 |
| 6 | Rushendra Varma Mudunuru | 814 | 275 | 29 | Provisioning 32Access & security 168Configuration 7563 unscored | access-analyzer bedrock budgets cloudtrail +15 |
| 7 | Dhiraj Ambekar | 671 | 184 | 22 | Provisioning 54Deployment 56Access & security 29Configuration 4536 unscored | amplify autoscaling cloudformation ec2 +6 |
| 8 | Aziz Bohra | 327 | 138 | 10 | Provisioning 17Configuration 12135 unscored | q route53 ses sts |
| 9 | Akash Kumar | 102 | 36 | 6 | Provisioning 5Deployment 6Access & security 3Configuration 2215 unscored | amplify ec2 q route53 +1 |
| 10 | Rushikesh Powar | 45 | 21 | 8 | Provisioning 1Configuration 204 unscored | ec2 route53 s3 |
| 11 | Jitu Prosad Saha | 38 | 13 | 3 | Provisioning 2Deployment 3Configuration 85 unscored | amplify route53 ses |
| 12 | Pranav Ojha | 0 | 0 | 2 | 3 unscored | |
| 13 | MOHD NAVED | 0 | 0 | 1 | 3 unscored |
Access posture
Read off the sign-in events already ingested. Not part of any score.
This says nothing about how well anyone works and feeds no ranking. It is here because CloudTrail records whether a console sign-in used MFA, this platform already reads CloudTrail, and reporting infrastructure work while sitting on evidence that none of it is protected would be a strange kind of silence.
| AWS user | Sign-ins | With MFA | Failed | IPs |
|---|---|---|---|---|
| pankaj | 29 | none | 17 | |
| dhiraj | 26 | none | 25 | |
| Harsh_Patel | 19 | none | 15 | |
| Rushendra_Verma | 14 | none | 9 | |
| ankur@kyma.world | 12 | none | 8 | |
| Akash | 8 | none | 8 | |
| abhishek | 6 | none | 6 | |
| Jitu_Shah | 2 | none | 1 | |
| Aziz-Bohra | 1 | none | 7 | 1 |
| Abhishek_K | 43 | 1 | 3 | 11 |
| Anshuman_P | 21 | 5 | 18 | |
| Harsh-V | 17 | 17 | 6 | |
| Rushendra_V | 13 | 13 | 13 | |
| Aziz-B | 9 | 9 | 1 | 9 |
| Pankaj-S | 8 | 8 | 5 | |
| Dhiraj-A | 4 | 4 | 4 | |
| Ankur | 2 | 2 | 2 |
How a change is weighted
The whole formula.
Brought infrastructure into existence or removed it — stacks, instances, load balancers, databases, apps.
Shipped a change to a running environment — builds, releases, environment rebuilds.
Changed who or what can reach something — security groups, IAM policies, keys, bucket policies.
Tuned infrastructure that already existed — attributes, scaling settings, DNS records.
Signing in, securing your own login, opening a shell. Presence, not delivery — scored at zero.
Where the work happened
AWS services touched, by change count.