AWS Onboarding
NimbusGuard connects to your AWS accounts using an IAM role with an external ID (AssumeRole). Customer credentials are never stored.
How it works
- You create an IAM role in your AWS account that trusts NimbusGuard's principal, scoped by a unique external ID.
- You register the account (and optionally an AWS Organization) in NimbusGuard.
- NimbusGuard assumes the role to run read-only inventory and posture scans on the cadence configured for your organization.
:::note No credentials stored NimbusGuard stores the role ARN and external ID — never your AWS access keys. :::
:::warning Placeholder ⚠️ Add the CloudFormation / Terraform snippet for the IAM role, the required read-only permissions, and step-by-step screenshots. :::