INTEGRATIONSCLOUD INFRASTRUCTURE
Amazon Web Services28 OF 28 CAPABILITIES ASSESSED
Every AWS identity, role and resource, mapped to who holds it
Identity Center permission sets, IAM roles and the resources they reach, mapped per account with group membership granted from Ploy.
TYPE · INFRAAUTH · IAM ROLEDOMAIN · AWS.AMAZON.COM
2.1WHAT IT UNLOCKS
Three jobs this connector does on day one
ACCOUNTS AND ROLES
One map across every AWS account
IAM roles, policies and groups, Identity Center permission sets and the accounts they apply to all land in the graph, so access is read once rather than account by account.
PROVISIONING
Identity Center membership is the grant
An approved request creates the Identity Center user where one is needed and writes the group membership the permission set hangs off. Writes only run when the integration has write access turned on.
REVIEWS AND EVIDENCE
Who could reach production, answered
Reviews resolve every entitlement to the identity holding it and to the EC2 instance, S3 bucket, database, queue or function it reaches.
2.4OFTEN CONNECTED TOGETHER