Skip to main content
AWS is a cloud-platform data source. Flint AI reads your AWS account and discovers the AI resources deployed in it. Flint AI reads the account through an IAM role it assumes, not through access keys, and the role is read-only. You create that role by deploying a CloudFormation template that Flint AI provides, then give Flint AI the role’s Amazon Resource Name (ARN). To open this page, go to Settings, then Data sources, select AWS, and open the Setup tab.
Connecting or editing the AWS data source requires an administrator. With a lower role you can still open the source and read its Scans tab.

Connect your account

The Setup tab walks you through downloading a CloudFormation template, deploying it in AWS to create a read-only role, and giving Flint AI that role’s ARN. The role is a single IAM role, FlintAIReadOnlyAccessRole, and IAM roles are global, so you deploy one stack and Flint AI reaches every active region from it. There is no per-region setup.
1

Download the CloudFormation template

On the AWS source’s Setup tab, select Download CloudFormation template. The template defines the read-only role scoped to the resources Flint AI scans, and it takes no parameters.
2

Open CloudFormation in the AWS console

Sign in to the AWS console. From the dashboard, search for and select CloudFormation.
3

Start a new stack

Select Stacks in the left navigation, then Create stack. If you have existing stacks, select Create stack in the top-right corner, then With new resources (standard).
4

Upload the template

In Prerequisite - Prepare template, confirm Choose an existing template is selected. In Specify template, select Upload a template file, then Choose file, and upload the template you downloaded from Flint AI. Select Next.
5

Name the stack

On the Specify stack details page, enter a Stack name. The template defines no parameters, so there is nothing else to fill in. Select Next.
6

Configure stack options

You can leave the Configure stack options page at its defaults. Adding Tags is optional. At the bottom, under Capabilities, select I acknowledge that AWS CloudFormation might create IAM resources with custom names, then select Next.
7

Review and submit

On the Review and create page, select Submit. Wait until the stack’s status is CREATE_COMPLETE.
8

Copy the role ARN

Go to the IAM console, select Roles, and open the role named FlintAIReadOnlyAccessRole that the stack created. On its Summary, copy the role’s Amazon Resource Name (ARN).
9

Connect the account

Back on the Setup tab, paste the ARN into IAM role ARN, then select Connect to save the connection. You can select Test connection to confirm Flint AI can assume the role. If the test fails, check the ARN and that the stack deployed cleanly, then try again. Once connected and tested, select Start scan to scan the account right away.
You connect one AWS account at a time.

What Flint AI scans

Once connected, Flint AI scans your account across its active regions and discovers:
  • Amazon Bedrock models and agents
  • Amazon Lex bots
  • Amazon SageMaker models

The Scans tab

Open the Scans tab to see the connected account, with an overall status and the date of its latest activity. Before the first scan runs, the account shows Never scanned and no date. Once scanning starts, the status reflects the account’s scans. Expand the account row to see a scan per service Flint AI covers, one each for Bedrock models, Bedrock agents, Lex bots, and SageMaker models. Each scan lists its Scan name, Status, and Started and Ended times: The tab refreshes on its own while a scan is running, so you can watch a scan move from In progress to Completed without reloading.

Next steps

Read your discovery results

Work out what needs attention first, whether a finding is real, and when it’s resolved

Connect another data source

Add a repository or another cloud platform to widen your inventory