Skip to main content
Connect an AWS account to add its resources, identities, and relationships to your Asset Map.

What it maps

Relationships show how these resources connect, including which security groups apply to an instance and which principals a role trusts.

Access required

The integration uses a read-only IAM role in your AWS account. Attach these AWS-managed policies: Antigen assumes the role using temporary credentials. You do not need to create or share an IAM user’s access keys. See AWS role-based access for how this works. You’ll need permission in AWS to create an IAM role and attach these policies.

Connect your account

1. Get the trust policy

Open Settings → Integrations → AWS. Copy the trust policy provided during setup. It identifies the Antigen role allowed to access your account and includes an external ID specific to this connection.

2. Create the IAM role

In the AWS IAM console:
  1. Open Roles → Create role.
  2. Choose Custom trust policy and paste the policy from Antigen.
  3. Attach SecurityAudit and ViewOnlyAccess.
  4. Name the role antigen-readonly and create it.
See Create a role using a custom trust policy for AWS’s instructions.

3. Complete the connection

Copy the new role’s ARN and return to Antigen. Enter the role ARN and the regions you want to include, such as us-east-1 and us-west-2, then select Connect. Antigen checks that it can assume the role and starts discovering resources. They appear in your Asset Map as the sync progresses. Repeat these steps for each AWS account you want to connect.

Troubleshooting

The role cannot be assumed

Check that the role ARN is correct and its trust policy matches the policy provided during setup, including the external ID.

Resources are missing

Check that the connection includes the region containing those resources. Confirm that both required policies are attached to the role and that your organization’s AWS policies allow the required read operations.