AWS onboarding
Set up a secure cross-account IAM role, validate the External ID, and connect AWS without saving long-lived keys.
CloudFormation setup
Use the ARCO Governance onboarding template to create a read-only scanner role, configure the External ID, and return the role ARN to the workspace.
Terraform setup
Teams managing AWS with Terraform can create the same cross-account IAM role and trust policy through infrastructure code.
Manual IAM role setup
Manual setup is available when change control requires reviewing each IAM policy statement before deployment.
Common errors
Most connection issues come from a missing External ID condition, an incorrect role ARN, or incomplete scanner permissions.
Ready for the next step?
Continue from this guide into the ARCO Governance workspace.
Related guides
Reports and readiness
Understand readiness views, report types, exports, and plan limits.
Read guideWhat ARCO scans
Review AWS posture checks, framework mapping, findings, evidence signals, and readiness states.
Read guidePricing and plans
Compare Starter, Growth, Scale, scan limits, export limits, and evidence ZIP availability.
Read guide