AWS Permissions
Introduction
AWS Permissions are the least-privilege policies CoreStack requires to onboard and manage an AWS account. CoreStack uses these permissions to ingest cost, inventory, configuration, and security data from your account, and — where read-write access is granted — to execute policy-based remediation. This page is relevant before onboarding any AWS account, or when adding a new product (FinOps, SecOps) to an existing one. It applies to Account Admin and Provider Admin users who manage cloud account onboarding.
How It Works
Once AWS permissions are granted, CoreStack ingests ten categories of data on independent schedules: cost and usage data every 6 hours via the Cost and Usage Report (CUR 1.0/2.0) delivered to Amazon S3; inventory and configuration data every 24 hours (configurable) via AWS describe/list APIs; utilization metrics on a 4, 8, or 24-hour user-selectable interval via Amazon CloudWatch; policy and guardrail evaluation results every 24 hours; activity and audit events near real-time via AWS CloudTrail; threat findings near real-time once GuardDuty is customer-configured; vulnerability data periodically via Amazon Inspector; access-posture data every 24 hours; and price-list and SKU master data every 24 hours. Each ingestion path runs as an independently observable process with its own run history and on-demand re-run, visible in Governance > Cloud Accounts > Account Status & Configurations.
Refer to the following user guides to get a summary of which least privilege policies are required to setup in your AWS cloud portal for different products and access levels:
Updated 3 days ago