What it is
One IAM role, CloudCtrlPayerRole, in your organization's management account. You create it yourself from a CloudFormation template we hand you, so it exists only because you applied it.
It trusts exactly four roles: the Cloud_CTRL functions in your own workload account that read from the management account. They are named by their full ARN, not by account and not by wildcard, so no other principal in that account can take the role by creating a role with a matching name.
Nothing holds a long-lived key to it. Each read assumes the role for a short-lived session, and every session is named, so it shows up in your management account's CloudTrail as cloud-ctrl- followed by the area it was reading.
What it can read
| Service | What it reads |
|---|---|
| AWS Organizations | Accounts, organizational units and the service control policies attached to them |
| Cost Explorer | Cost and usage, the month-end forecast, cost allocation tags, Savings Plans coverage and utilization, cost anomalies |
| Savings Plans and Reserved Instances | The terms still running and when each one ends |
| AWS Budgets | Your budgets, to compare spend against |
| Cost Optimization Hub, Compute Optimizer | Savings and rightsizing recommendations |
| AWS Control Tower | The landing zone and the controls enabled on it |
| AWS Health | Events across the organization, and the accounts and resources they affect |
| Security Hub, GuardDuty | Findings, and which Regions the finding read covered |
| IAM Access Analyzer | External-access findings |
| IAM | The credential report, for the identity controls on Security |
| AWS Config | The resource inventory, through an organization-wide aggregator |
| CloudTrail | Recent management events, looked up rather than exported |
It also reads whether each of these services is switched on. That is how a page can say "Security Hub is not enabled" instead of showing an empty list that looks like good news.
What it cannot do
No enable, update, put, create or delete action appears in it, for any service. It cannot change a setting, turn a service on, activate a cost allocation tag, or touch a resource. Everything that has to be switched on is switched on by you, from your own account.
One call is not strictly a read: iam:GenerateCredentialReport asks IAM to build the credential report that the next call reads. It changes no setting and no identity.
Why the policy says Resource: "*". Most of these actions accept no resource ARN at all, by AWS's own API design. The limit is in the list of actions, which is read-only throughout.
How to remove it
Delete the CloudFormation stack that created the role. Our access to the management account ends at once, and the pages that read from it stop answering.
Two things it deliberately leaves in place:
- The services you turned on stay on. Cost Explorer, Security Hub, GuardDuty and the rest were switched on by you, and turning them off would need exactly the write access this role refuses to hold. Turn them off yourself if you want to.
- CloudFormation StackSets trusted access, if you enabled it. Setting up Resource Explorer across the organization can ask for it, so new accounts enrol themselves. Removing the role does not undo it; revoke it in Organizations.
What it does not need
The activity feed reads your workload account's own CloudTrail event history, with the dashboard's own credentials rather than through this role. You do not have to configure a trail.