Connecting or editing the AWS data source requires an administrator. With a lower role you can
still open the source and read its Scans tab.
Connect your account
The Setup tab walks you through downloading a CloudFormation template, deploying it in AWS to create a read-only role, and giving Flint AI that role’s ARN. The role is a single IAM role,FlintAIReadOnlyAccessRole, and IAM roles are global, so you deploy one stack and Flint AI
reaches every active region from it. There is no per-region setup.
1
Download the CloudFormation template
On the AWS source’s Setup tab, select Download CloudFormation template. The
template defines the read-only role scoped to the resources Flint AI scans, and it takes no
parameters.
2
Open CloudFormation in the AWS console
Sign in to the AWS console. From the dashboard, search for and select CloudFormation.
3
Start a new stack
Select Stacks in the left navigation, then Create stack. If you have existing
stacks, select Create stack in the top-right corner, then With new resources
(standard).
4
Upload the template
In Prerequisite - Prepare template, confirm Choose an existing template is
selected. In Specify template, select Upload a template file, then Choose file,
and upload the template you downloaded from Flint AI. Select Next.
5
Name the stack
On the Specify stack details page, enter a Stack name. The template defines no
parameters, so there is nothing else to fill in. Select Next.
6
Configure stack options
You can leave the Configure stack options page at its defaults. Adding Tags is
optional. At the bottom, under Capabilities, select I acknowledge that AWS
CloudFormation might create IAM resources with custom names, then select Next.
7
Review and submit
On the Review and create page, select Submit. Wait until the stack’s status is
CREATE_COMPLETE.8
Copy the role ARN
Go to the IAM console, select Roles, and open the role named
FlintAIReadOnlyAccessRole that the stack created. On its Summary, copy the role’s
Amazon Resource Name (ARN).9
Connect the account
Back on the Setup tab, paste the ARN into IAM role ARN, then select Connect to
save the connection. You can select Test connection to confirm Flint AI can assume the
role. If the test fails, check the ARN and that the stack deployed cleanly, then try again.
Once connected and tested, select Start scan to scan the account right away.
What Flint AI scans
Once connected, Flint AI scans your account across its active regions and discovers:- Amazon Bedrock models and agents
- Amazon Lex bots
- Amazon SageMaker models
The Scans tab
Open the Scans tab to see the connected account, with an overall status and the date of its latest activity. Before the first scan runs, the account shows Never scanned and no date. Once scanning starts, the status reflects the account’s scans. Expand the account row to see a scan per service Flint AI covers, one each for Bedrock models, Bedrock agents, Lex bots, and SageMaker models. Each scan lists its Scan name, Status, and Started and Ended times:
The tab refreshes on its own while a scan is running, so you can watch a scan move from
In progress to Completed without reloading.
Next steps
Read your discovery results
Work out what needs attention first, whether a finding is real, and when it’s resolved
Connect another data source
Add a repository or another cloud platform to widen your inventory

