AWS Access

Access states reference

Every connection state you can see during onboarding, what it means, and what the next action is when something has not worked.

Currentengine 9.0.0Verified 2026-08-30

Connection states

StateMeaningNext action
NOT_CONNECTEDNothing attempted yetOpen your onboarding link
AUTHORIZATION_REQUIREDYou have been asked to authorize accessEnter your AWS account ID
PROVISIONINGAccount ID recorded, stack not yet verifiedCreate the stack, then press Verify
VERIFYINGA verification run is in flightWait. This is the system's move
CONNECTEDA real run assumed the role and the boundary heldNothing. The assessment dispatches on its own
FAILEDVerification ran and did not passRead the reported reason below
EXPIREDThe engagement expiry has passedUpdate the stack with a new expiry
REVOKEDAccess has been withdrawnRe-authorize if the engagement is continuing

Only CONNECTED permits an assessment, and it is reachable only through a verification run.

Common reasons verification does not pass

CauseWhat to check
The stack has not finishedWait for CREATE_COMPLETE, then verify again
The identity provider option was answered the other wayThe stack will have failed loudly. Re-run it with the box the other way
The engagement expiry has already passedThe role denies everything. Update the stack with a new expiry
A role of that name exists but is not oursReported as a conflict. Nothing is touched until it is resolved
The role carries grants the template never attachedReported as a conflict. Nothing is touched

How the state was established

Alongside the state, each engagement records the method: a real OIDC verification, an operator's assertion, or none. The distinction between a measurement and somebody's judgement is the point of recording it at all.