Docs / Integration Guides / AWS account discovery
AWS account discovery
Integration guide
This is for auditing a client's own AWS account as part of InfraAudit's cloud collection (IAM users/roles, security groups, S3 bucket policies, etc.) — it's a separate thing from Graften's own AWS Marketplace billing integration, which is about how *you* get billed for Graften itself, not about auditing a client.
Setup
- From the client's record, go to Connections → Add Connection → AWS.
- Graften needs a read-only IAM role in the client's AWS account, set up via a cross-account trust relationship (the client creates a role that trusts Graften's AWS account ID, scoped to read-only permissions — Graften never asks for a client's long-lived AWS access keys).
- Once the role ARN is added in Graften, POST /api/v1/audit/run will include AWS findings in that client's next InfraAudit run.
Scope of what's collected
IAM users/roles/policies (flagging unused or overly-permissive ones), security group rules (especially anything open to 0.0.0.0/0), S3 bucket public-access settings, and basic resource inventory. This is a security posture audit, not a cost/billing audit — for that, point the client to AWS Cost Explorer directly.
Open in the interactive docs