Governance Concepts
Engagement
One customer, one AWS account, one assessment lifecycle. It is the unit that carries scope, access, status and delivery from enquiry to board pack.
What it is
The record of one piece of work for one customer against one AWS account. It carries the offering, the scope, the access state, the assessment status and the delivery record.
Why it exists
Access, scope and results all have to be attributable to something. The engagement is what a session name in your CloudTrail refers to, what an expiry date is set against, and what a board pack belongs to.
How GovIntel applies it
Each engagement has its own reference, its own expiry, and its own access. Two engagements against the same account share one role, re-tagged and re-dated rather than duplicated, because there is one role per account always.
What it does not mean
It is not an account, not a subscription and not a contract term. An engagement ends; the relationship may continue with a new one.
