A role that can read your organization and change nothing in it.

Cloud_CTRL reads the management account through one IAM role, created from a template you can read line by line before you apply it. Delete it, and our access ends.

What it is

One IAM role, CloudCtrlPayerRole, in your organization's management account. You create it yourself from a CloudFormation template we hand you, so it exists only because you applied it.

It trusts exactly four roles: the Cloud_CTRL functions in your own workload account that read from the management account. They are named by their full ARN, not by account and not by wildcard, so no other principal in that account can take the role by creating a role with a matching name.

Nothing holds a long-lived key to it. Each read assumes the role for a short-lived session, and every session is named, so it shows up in your management account's CloudTrail as cloud-ctrl- followed by the area it was reading.

What it can read

ServiceWhat it reads
AWS OrganizationsAccounts, organizational units and the service control policies attached to them
Cost ExplorerCost and usage, the month-end forecast, cost allocation tags, Savings Plans coverage and utilization, cost anomalies
Savings Plans and Reserved InstancesThe terms still running and when each one ends
AWS BudgetsYour budgets, to compare spend against
Cost Optimization Hub, Compute OptimizerSavings and rightsizing recommendations
AWS Control TowerThe landing zone and the controls enabled on it
AWS HealthEvents across the organization, and the accounts and resources they affect
Security Hub, GuardDutyFindings, and which Regions the finding read covered
IAM Access AnalyzerExternal-access findings
IAMThe credential report, for the identity controls on Security
AWS ConfigThe resource inventory, through an organization-wide aggregator
CloudTrailRecent management events, looked up rather than exported

It also reads whether each of these services is switched on. That is how a page can say "Security Hub is not enabled" instead of showing an empty list that looks like good news.

What it cannot do

No enable, update, put, create or delete action appears in it, for any service. It cannot change a setting, turn a service on, activate a cost allocation tag, or touch a resource. Everything that has to be switched on is switched on by you, from your own account.

One call is not strictly a read: iam:GenerateCredentialReport asks IAM to build the credential report that the next call reads. It changes no setting and no identity.

Why the policy says Resource: "*". Most of these actions accept no resource ARN at all, by AWS's own API design. The limit is in the list of actions, which is read-only throughout.

How to remove it

Delete the CloudFormation stack that created the role. Our access to the management account ends at once, and the pages that read from it stop answering.

Two things it deliberately leaves in place:

What it does not need

The activity feed reads your workload account's own CloudTrail event history, with the dashboard's own credentials rather than through this role. You do not have to configure a trail.

Also in Assurance

Point it at your organization and see the first answer the same afternoon.

30 minutes of one engineer · your AWS data stays in your account

Book a walkthrough