Skip to main content

Connect AWS

Connect your AWS environment to start exploring resources and security findings in Byrsa. Have your AWS administrator help with the deployment and review of the connection permissions.

Connect an individual account​

  1. Open Cloud Accounts and choose Add Account.
  2. Select the individual AWS account option.
  3. Generate the external ID and enter a name for the connection.
  4. Use the setup dialog's deployment action or copy its CloudFormation template for your administrator to deploy.
  5. Once deployment finishes, copy the stack's RoleArn output into Byrsa.
  6. Complete the connection check and save.

Use the external ID supplied by the setup dialog. Your administrator should review the permissions in the generated template before deploying it.

Connect an organization​

  1. Choose the AWS organization option.
  2. Provide the management-account and organization root details requested by the dialog.
  3. Have your administrator deploy the organization template and complete its member-account setup.
  4. Enter the target account IDs and run the per-account connection tests.
  5. Review any failures before saving.

Check that each intended member account is included and connected. When adding accounts later, verify their setup and collection rather than assuming they are already covered.

After connecting​

Open Inventory to look for collected resources, then use Dashboard → Coverage to review freshness. A successful connection may need time to populate data.

To see runtime findings, Amazon Inspector must also be enabled and producing findings for the relevant workloads.

Manage a connection​

Use Cloud Accounts to review connection status, rename an account, and use the available connect/disconnect controls. Before relying on disconnection to stop collection, ask your administrator to confirm the deployment's collection behavior.

If something is missing​

  • Connection fails: ask your administrator to check the deployed role, external ID, and completed setup.
  • No inventory: check the account selection and collection status.
  • No runtime findings: check Inspector coverage and collection.
  • Missing organization member: review its account ID and individual connection-test result.