What it maps
Relationships show how these resources connect, including which security groups apply to an instance and which principals a role trusts.
Access required
The integration uses a read-only IAM role in your AWS account. Attach these AWS-managed policies:
Antigen assumes the role using temporary credentials. You do not need to create or share an IAM user’s access keys. See AWS role-based access for how this works.
You’ll need permission in AWS to create an IAM role and attach these policies.
Connect your account
1. Get the trust policy
Open Settings → Integrations → AWS. Copy the trust policy provided during setup. It identifies the Antigen role allowed to access your account and includes an external ID specific to this connection.2. Create the IAM role
In the AWS IAM console:- Open Roles → Create role.
- Choose Custom trust policy and paste the policy from Antigen.
- Attach SecurityAudit and ViewOnlyAccess.
- Name the role
antigen-readonlyand create it.
3. Complete the connection
Copy the new role’s ARN and return to Antigen. Enter the role ARN and the regions you want to include, such asus-east-1 and us-west-2, then select Connect.
Antigen checks that it can assume the role and starts discovering resources. They appear in your Asset Map as the sync progresses.
Repeat these steps for each AWS account you want to connect.