AWS onboarding
Set up a secure cross-account IAM role, validate the External ID, and connect AWS without saving long-lived keys.
CloudFormation setup
Use the ARCO Governance onboarding template to create a read-only scanner role, configure the External ID, and return the role ARN to the workspace.
Terraform setup
Teams managing AWS with Terraform can create the same cross-account IAM role and trust policy through infrastructure code.
Manual IAM role setup
Manual setup is available when change control requires reviewing each IAM policy statement before deployment.
Common errors
Most connection issues come from a missing External ID condition, an incorrect role ARN, or incomplete scanner permissions.
Ready for the next step?
Continue from this guide into the ARCO Governance workspace.
Related guides
Reports and readiness
Understand ARCO Governance readiness views, AWS report types, evidence exports, auditor packets, certification boundaries, and plan limits.
Read guideWhat ARCO scans
See how ARCO Governance scans AWS posture, maps findings to SOC 2, HIPAA, and PCI DSS controls, and presents evidence and readiness states.
Read guidePricing and plans
Compare ARCO Governance Starter, Growth, and Scale plans, including AWS account limits, scan frequency, report exports, evidence ZIPs, and support.
Read guide