AWS Access
Access states reference
Every connection state you can see during onboarding, what it means, and what the next action is when something has not worked.
Currentengine 9.0.0Verified 2026-08-30
Connection states
| State | Meaning | Next action |
|---|---|---|
NOT_CONNECTED | Nothing attempted yet | Open your onboarding link |
AUTHORIZATION_REQUIRED | You have been asked to authorize access | Enter your AWS account ID |
PROVISIONING | Account ID recorded, stack not yet verified | Create the stack, then press Verify |
VERIFYING | A verification run is in flight | Wait. This is the system's move |
CONNECTED | A real run assumed the role and the boundary held | Nothing. The assessment dispatches on its own |
FAILED | Verification ran and did not pass | Read the reported reason below |
EXPIRED | The engagement expiry has passed | Update the stack with a new expiry |
REVOKED | Access has been withdrawn | Re-authorize if the engagement is continuing |
Only CONNECTED permits an assessment, and it is reachable only through a verification run.
Common reasons verification does not pass
| Cause | What to check |
|---|---|
| The stack has not finished | Wait for CREATE_COMPLETE, then verify again |
| The identity provider option was answered the other way | The stack will have failed loudly. Re-run it with the box the other way |
| The engagement expiry has already passed | The role denies everything. Update the stack with a new expiry |
| A role of that name exists but is not ours | Reported as a conflict. Nothing is touched until it is resolved |
| The role carries grants the template never attached | Reported as a conflict. Nothing is touched |
How the state was established
Alongside the state, each engagement records the method: a real OIDC verification, an operator's assertion, or none. The distinction between a measurement and somebody's judgement is the point of recording it at all.
