> ## Documentation Index
> Fetch the complete documentation index at: https://docs.switchagents.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs moved from docs.flintai.dev to docs.switchagents.ai. Use docs.switchagents.ai for every link and request.
> To search these docs from an AI tool, connect the MCP server at https://docs.switchagents.ai/mcp. The page index is at https://docs.switchagents.ai/llms.txt.

# AWS

> Connect an AWS account so Switch Trust can scan it for deployed AI resources

AWS is a cloud-platform data source. Switch Trust reads your AWS account and discovers the AI
resources deployed in it. Switch Trust reads the account through an IAM role it assumes, not
through access keys, and the role is read-only. You create that role by deploying a
CloudFormation template that Switch Trust provides, then give Switch Trust the role's Amazon Resource
Name (ARN).

To open this page, go to **Settings**, then **Data sources**, select **AWS**, and open the
**Setup** tab.

<Note>
  Connecting or editing the AWS data source requires an administrator. With a lower role you can
  still open the source and read its **Scans** tab.
</Note>

## Connect your account

The **Setup** tab walks you through downloading a CloudFormation template, deploying it in AWS
to create a read-only role, and giving Switch Trust that role's ARN. The role is a single IAM role,
`FlintAIReadOnlyAccessRole`, and IAM roles are global, so you deploy one stack and Switch Trust
reaches every active region from it. There is no per-region setup.

<Steps>
  <Step title="Download the CloudFormation template">
    On the **AWS** source's **Setup** tab, select **Download CloudFormation template**. The
    template defines the read-only role scoped to the resources Switch Trust scans, and it takes no
    parameters.
  </Step>

  <Step title="Open CloudFormation in the AWS console">
    Sign in to the AWS console. From the dashboard, search for and select **CloudFormation**.
  </Step>

  <Step title="Start a new stack">
    Select **Stacks** in the left navigation, then **Create stack**. If you have existing
    stacks, select **Create stack** in the top-right corner, then **With new resources
    (standard)**.
  </Step>

  <Step title="Upload the template">
    In **Prerequisite - Prepare template**, confirm **Choose an existing template** is
    selected. In **Specify template**, select **Upload a template file**, then **Choose file**,
    and upload the template you downloaded from Switch Trust. Select **Next**.
  </Step>

  <Step title="Name the stack">
    On the **Specify stack details** page, enter a **Stack name**. The template defines no
    parameters, so there is nothing else to fill in. Select **Next**.
  </Step>

  <Step title="Configure stack options">
    You can leave the **Configure stack options** page at its defaults. Adding **Tags** is
    optional. At the bottom, under **Capabilities**, select **I acknowledge that AWS
    CloudFormation might create IAM resources with custom names**, then select **Next**.
  </Step>

  <Step title="Review and submit">
    On the **Review and create** page, select **Submit**. Wait until the stack's status is
    `CREATE_COMPLETE`.
  </Step>

  <Step title="Copy the role ARN">
    Go to the **IAM** console, select **Roles**, and open the role named
    `FlintAIReadOnlyAccessRole` that the stack created. On its **Summary**, copy the role's
    **Amazon Resource Name (ARN)**.
  </Step>

  <Step title="Connect the account">
    Back on the **Setup** tab, paste the ARN into **IAM role ARN**, then select **Connect** to
    save the connection. You can select **Test connection** to confirm Switch Trust can assume the
    role. If the test fails, check the ARN and that the stack deployed cleanly, then try again.
    Once connected and tested, select **Start scan** to scan the account right away.
  </Step>
</Steps>

You connect one AWS account at a time.

## What Switch Trust scans

Once connected, Switch Trust scans your account across its active regions and discovers:

* **Amazon Bedrock** models and agents
* **Amazon Lex** bots
* **Amazon SageMaker** models

## The Scans tab

Open the **Scans** tab to see the connected account, with an overall status and the date of its
latest activity. Before the first scan runs, the account shows **Never scanned** and no date.
Once scanning starts, the status reflects the account's scans.

Expand the account row to see a scan per service Switch Trust covers, one each for Bedrock models,
Bedrock agents, Lex bots, and SageMaker models. Each scan lists its **Scan** name, **Status**,
and **Started** and **Ended** times:

| Status | What it means |
| - | - |
| **Pending** | The scan is queued |
| **In progress** | The scan is running |
| **Completed** | The scan finished |
| **Canceled** | The scan was stopped before it finished |

The tab refreshes on its own while a scan is running, so you can watch a scan move from
**In progress** to **Completed** without reloading.

## Next steps

<CardGroup cols={2}>
  <Card title="Read your discovery results" icon="triangle-exclamation" href="/switch-trust/discovery/results">
    Work out what needs attention first, whether a finding is real, and when it's resolved
  </Card>

  <Card title="Connect another data source" icon="plug" href="/switch-trust/admin/data-sources">
    Add a repository or another cloud platform to widen your inventory
  </Card>
</CardGroup>
