Connect an AWS account
betaGive agents AWS API access controlled by your IAM role, from web, Slack, Teams, or trusted managed email.
A workspace admin can connect an AWS account using a customer-owned IAM role. Your AWS IAM policy determines the available operations. Authorized chats can use permitted writes and sensitive data reads. Scheduled wakeups require a separate explicit grant and are limited to reviewed infrastructure and cost reads. AWS access must be enabled for the workspace.
Connect from chat
Ask your agent to investigate AWS and name the account and Region. If the account is not connected, the agent can show a Connect AWS account card in web chat. A workspace admin can open role setup over the conversation. Check the account, Region and workspace before continuing. AWS access is separate from the connector catalog; you do not need to install a CLI or upload access keys.
The card resumes an existing unfinished connection. If several connections could apply, select the one to use. An already connected account offers Continue investigation. After successful verification, Verify and continue resumes the original investigation with that connection and read-only access. If the agent is busy or continuation fails, use Continue investigation when it becomes available; the connection is preserved. Revoked or unavailable connections require review in Cloud accounts.
If you are not a workspace admin, share the Cloud accounts link with an administrator. Account setup does not authorize a scheduled check. Scheduled checks still need their separate grant. Other chat surfaces direct users to Cloud accounts rather than opening setup there.
Connect your account
- Open Settings → Infrastructure access → Cloud accounts, choose the workspace, and select Connect account. Select Amazon Web Services (AWS) and enter a connection name, 12-digit AWS account ID, and Region. Connections belong to the selected workspace. Old AWS settings links still open this page with the original workspace selected.
- Select Continue to role setup, then choose CloudFormation, Terraform, AWS CLI, or AWS Console. CloudFormation provides a template and stack parameters; Terraform provides a configuration file; AWS CLI provides policy files and commands; AWS Console provides manual steps and policy JSON. Apply the role in the specified AWS account through your reviewed infrastructure workflow. Each method uses the connection’s d5s principal, external ID and regional starter permissions.
- Select Continue to verification, paste the resulting role ARN, and select Verify connection. Verification checks the account identity and rejects trust that accepts a missing or alternate external ID. Use the supplied exact trust policy. The connection becomes Connected when those checks pass; AWS checks service permissions on each operation. If verification fails, check the account, ARN and trust policy, then retry. You can close setup and return through View details → Resume setup without creating another connection.
- In a web chat, an authorized Slack or Teams conversation, or trusted managed email, ask the agent to list AWS connections, then make a targeted request. If several accounts are connected, name the one to use.
Choose permissions in AWS
Creating the role and its trust policy grants the displayed d5s principal access under the attached IAM policy. Verification confirms the connection; it does not create the AWS trust or grant additional permissions.
The supplied template starts with a read-only policy for EC2, ECS, EKS, RDS, load balancers and CloudWatch discovery in the selected Region. Those are starter examples, not a limit on the tool. Narrow or broaden the role policy in your IaC, including attaching AdministratorAccess when you want admin capabilities. IAM boundaries, organization policies, resource policies and explicit denies still apply.
An admin role permits agents to create, change or delete AWS resources. A role that allows Secrets Manager, SSM decrypted parameters or resource data may return those values to the agent. Choose the policy for the data and actions you want to delegate. No connection credential is placed in the agent sandbox, but intentionally requested API data can appear in the agent's answer and follow normal conversation retention.
An existing IAM user key pair can provision this role through your normal infrastructure workflow. This version does not accept access-key uploads. It uses temporary role credentials within d5s.
Use AWS commands
The native aws tool accepts one SDK-modeled API operation using familiar CLI spelling, such as aws ec2 describe-instances or aws iam create-user --user-name engineer. AWS IAM accepts or denies it. Use s3api for S3 API operations; high-level CLI commands such as s3 cp, local configuration and login commands are not part of this API adapter.
String, numeric and boolean API flags are supported. Structures, maps and lists of structures accept AWS CLI shorthand, inline JSON, or --cli-input-json. Quote the whole shorthand argument when it contains inner quotes, escaped commas or spaces. For example:
aws ce get-cost-and-usage --region us-east-1 --time-period Start=2026-09-01,End=2026-09-30 --granularity MONTHLY --metrics UnblendedCost --filter 'Dimensions={Key=REGION,Values=[eu-central-1]}' --group-by Type=DIMENSION,Key=SERVICE Type=DIMENSION,Key=RECORD_TYPE
Use aws <service> <operation> help or --help to inspect parameter names, required fields and types. Help is local; it does not call AWS or confirm IAM permission. Malformed structured values identify the affected option without repeating its contents. A JSON object passed with --cli-input-json may be combined with explicit options, which take precedence.
--region overrides the connection's default Region when IAM allows it. --query supports JMESPath projection, and output is JSON. File references, including shorthand @=, are unavailable. There is no backend filesystem, local credential/profile override, custom endpoint, automatic pagination or event-stream transport. Ordinary response streams such as S3 object bodies return bounded base64 data.
Responses are bounded to 24,000 bytes and marked partial when trimmed. Narrow filters or page sizes before advancing a continuation token. Log queries default to the last hour when you omit a time window; you may supply an older window. API calls are not automatically retried. After a timeout or lost reply, inspect AWS state before repeating a mutation: it may already have completed.
Slack and Teams authorization
AWS workspace connections are shared capabilities of a coworker bound to a Slack or Teams channel. Channel members can ask that coworker to use its configured role under the existing conversation grant. A Slack DM uses its linked d5s user and current resource permissions. Every call rechecks the exact workspace, agent, binding or identity link, installation and source authorization; channel calls also recheck membership. A revoked grant or unavailable membership check fails closed. Audit attribution keeps the external actor rather than impersonating the agent owner.
Connecting a shared coworker to Slack or Teams delegates its configured shared capabilities to that conversation. If two audiences must not influence one another, use separate agents and appropriate IAM roles. Delegated and peer-initiated turns are not enabled in this pilot. Scheduled wakeups need the separate read-only grant described below.
Scheduled cost audits
A workspace connector admin can authorize one recurring, in-app agent wakeup without an end date or run-count limit to use one verified AWS connection. This is an explicit grant. The agent owner and the schedule itself do not grant AWS access.
Create the wakeup first. Then use the user-authenticated API:
POST /api/v1/workspaces/{workspace_id}/aws-investigation/connections/{connection_id}/scheduled-grants
Content-Type: application/json
{"scheduled_wakeup_id": "<wakeup UUID>"}
The admin must be allowed to run the agent. Each scheduled AWS call rechecks that admin's active membership, connector-admin role, resource access and AWS feature permission, together with the active agent, approved schedule and verified connection.
The grant covers the approved wakeup configuration. Editing its instructions, timing or delivery invalidates the grant. Authorize the new configuration before its next run. Pausing the wakeup, revoking its connection or deleting its grant stops its AWS reads. External delivery is not supported for these grants.
Scheduled commands have an additional reviewed read ceiling for infrastructure inventories, ECR manifests and lifecycle policies, CloudWatch utilization, Cost Explorer, pricing and Savings Plans. The customer role must also permit each read. The grant permits no image deletion, infrastructure change or commitment purchase.
List grants with GET .../{connection_id}/scheduled-grants. Revoke one with DELETE .../{connection_id}/scheduled-grants/{grant_id}. These routes require a user-authenticated workspace connector admin.
For a cost report, separate usage, credits and net charges. Use complete comparison periods, record AWS data freshness, and page bounded inventories before claiming full coverage. Recommendations do not authorize cleanup or purchases.
Trusted email authorization
AWS access from email requires a d5s-managed mailbox, a successful retained sender-domain verification, and the exact sender address in the mailbox's Trusted senders rules. A wildcard or domain-only trusted rule, correspondence history, a one-time quarantine release, an agent owner, or a matching From header is insufficient. The sender must still satisfy current inbound rules, the mailbox and contact must remain active, and the user who explicitly saved the trust policy must still be active with workspace membership and permission to run the agent.
This is an explicit delegation to that email address, not proof of an individual teammate's identity. Audits attribute the external sender and exact mailbox. Gmail and Microsoft connected mailboxes do not yet retain the required sender-verification evidence for this AWS pilot; use the web or a connected Slack/Teams conversation instead.
Revoke or troubleshoot
If the trusted d5s principal changes, update the role's trust policy through your infrastructure workflow, then verify the connection again. Use the exact principal and external ID shown in setup. Ordinary application updates do not require a trust-policy change. Deleting and recreating a trusted IAM role can break trust even when its name is unchanged; see AWS role principal guidance.
A workspace admin can revoke a connection under Cloud accounts → View details → Revoke access. Confirm the named account to revoke it. Remove the role trust or role in AWS as well to close the AWS side. Revocation blocks new commands and suppresses results from a call whose connection or source grant was revoked. It cannot undo a mutation already sent to AWS. d5s records command attempts and outcomes without raw inputs or results, including attempts whose result could not be delivered; AWS CloudTrail supplies upstream request detail for the events it records.
If verification fails, check that the role account matches the connection and the trust policy uses the displayed regional d5s principal and exact external ID. When AWS rejects an operation with AccessDenied, AccessDeniedException or UnauthorizedOperation, the agent receives a permission error naming the failed operation and Region. Review the connection’s IAM permissions, account policies and Region restrictions. In web chat, Review permissions opens guidance for that existing connection. It identifies the denied operation, Region and required IAM action when d5s has an exact mapping. Successful parts of the investigation remain valid; denied parts are reported as incomplete. Review the policy in AWS through your approved infrastructure workflow. d5s does not broaden IAM permissions. After your changes, continue the read-only investigation to check the denied operation. Role verification alone does not prove it is allowed. Scheduled read restrictions are separate from IAM permissions: widening IAM does not bypass them.
A permission rejection does not mean AWS is unavailable. A role-assumption rejection requires checking the broker permission and role trust as well. Verification establishes the connection identity, not permission for every API.
If a command uses an invalid parameter choice, the error identifies the option and its allowed values without repeating your input. For CloudWatch metrics, use space-separated values such as --statistics Average Maximum. Use --extended-statistics p95 for percentiles. Recognized AWS parameter rejections are command errors, not availability errors. Use aws <service> <operation> help, correct the parameters, then submit the command again.
An AWS access connection is separate from Kubernetes Satellite. AWS public APIs use the account role; Kubernetes API and private VPC service access require their own installation and grant.