Preferred read-only IAM role or encrypted legacy access key
Read-only account access and IAM summary calls
Read-only CloudTrail, GuardDuty, S3, RDS, and EC2 description calls
A deployment-owned principal assumes the customer role only when the role method is used
Setup path
Setup remains administrator-controlled inside the authenticated workspace.
Create the documented read-only role or legacy credential
Choose supported Regions and service families
Connect the account
Run and review the first collection
Collection limitations
A limited or failed read stays visible and never becomes a passing result.
Collection covers only selected supported Regions and service families
Service quotas and supported resource limits constrain collection
A failed or permission-limited read never counts as passing
Disconnect and deletion behavior
An administrator can disconnect the integration. Stored credentials and configuration are removed locally, connector-derived evidence is expired, and the event is audited. The customer should also remove the AWS role or access key.
Existing historical records remain available as review history
Connector-derived evidence is marked expired when the source is disconnected
Disconnect is organization-scoped and audit logged
A provider observation can support a control only after the right relationship and evidence are reviewed. Connecting Amazon Web Services does not automatically verify a control, complete a framework, or produce an audit conclusion.
Start with the roadmap
Put Amazon Web Services into a prioritized readiness plan.
Build the free roadmap first, then activate the AI vCISO when you are ready to connect the provider.