Skip to main content

AWS Onboarding

NimbusGuard connects to your AWS accounts using an IAM role with an external ID (AssumeRole). Customer credentials are never stored.

How it works

  1. You create an IAM role in your AWS account that trusts NimbusGuard's principal, scoped by a unique external ID.
  2. You register the account (and optionally an AWS Organization) in NimbusGuard.
  3. NimbusGuard assumes the role to run read-only inventory and posture scans on the cadence configured for your organization.

:::note No credentials stored NimbusGuard stores the role ARN and external ID — never your AWS access keys. :::

:::warning Placeholder ⚠️ Add the CloudFormation / Terraform snippet for the IAM role, the required read-only permissions, and step-by-step screenshots. :::