Skip to main content
AWS is the data source WeWatch builds its topology from. Connect it first — every other integration depends on it.

How access works

WeWatch creates a role in your account and assumes it. That means:
  • Role-based access. No long-term credentials or access keys are stored.
  • Read-only. The policy grants describe and list actions, not writes.
  • Revocable. Delete the role and access ends immediately.

Connect an account

1

Start the flow

Integrations → AWS → Add Connection.
2

Choose what to connect

Select the capabilities you want WeWatch to read and the deployment option for your environment.
3

Create the role

WeWatch generates a trust policy and a permissions policy scoped to what you selected. Apply them in your AWS account to create the role.
4

Confirm

Paste the role ARN back into WeWatch. The connection is verified and the first topology sync begins.
The first sync usually completes in under five minutes.

Connecting more accounts

Each AWS account is a separate connection. Repeat the flow for each one, then use Spaces to scope a conversation or investigation to a subset of them.

Revoking access

Remove the connection from Integrations → AWS, or delete the role in AWS. Either ends access immediately.
Removing a connection also removes the topology built from it. Past investigations keep their written findings but can no longer be re-run against live data.