Graften Docsgraften.io
Docs / Integration Guides / AWS account discovery

AWS account discovery

Integration guide

This is for auditing a client's own AWS account as part of InfraAudit's cloud collection (IAM users/roles, security groups, S3 bucket policies, etc.) — it's a separate thing from Graften's own AWS Marketplace billing integration, which is about how *you* get billed for Graften itself, not about auditing a client.

Setup

  1. From the client's record, go to Connections → Add Connection → AWS.
  2. Graften needs a read-only IAM role in the client's AWS account, set up via a cross-account trust relationship (the client creates a role that trusts Graften's AWS account ID, scoped to read-only permissions — Graften never asks for a client's long-lived AWS access keys).
  3. Once the role ARN is added in Graften, POST /api/v1/audit/run will include AWS findings in that client's next InfraAudit run.

Scope of what's collected

IAM users/roles/policies (flagging unused or overly-permissive ones), security group rules (especially anything open to 0.0.0.0/0), S3 bucket public-access settings, and basic resource inventory. This is a security posture audit, not a cost/billing audit — for that, point the client to AWS Cost Explorer directly.

Open in the interactive docs