How GovIntel Works
Getting started
What you need before connecting an AWS account to GovIntel, and what the person doing it will be asked to do.
Currentengine 9.0.0Verified 2026-08-30
What you need
| You need | Why |
|---|---|
| The 12-digit ID of the AWS account to assess | It is the only thing you type. The server derives the role identifier from it, so you never transcribe one |
| Someone who can create a CloudFormation stack in that account | Creating the read-only role is a one-screen operation, but it does require that permission |
| The onboarding link GovIntel emailed you | It opens once. If it has been used or has expired, ask for another |
You do not need to write an IAM policy, invent an expiry timestamp, create an access key, or supply any AWS credential.
What you will be asked
Four screens. You read what you are agreeing to, enter twelve digits, press Authorize, and press Verify when the stack has finished.
One choice is genuinely yours: whether the stack should create the GitHub Actions identity provider. It is ticked by default and is correct for most accounts. GovIntel cannot decide it for you, because it has no access to your account until the role exists. See Connecting your AWS account.
Before you start, worth reading
- The access model - what the role can and cannot do
- What is explicitly denied - the actions blocked outright
- What GovIntel does not do - so the deliverable is not a surprise
