Technical Concepts
Attributable session name
The naming rule that lets your CloudTrail distinguish one engagement's access from another's, enforced by the role's own trust policy.
What it is
Every session GovIntel opens in your account is named after the engagement and the run that created it, beginning govintel-.
Why it is enforced rather than conventional
The trust policy requires it. A session whose name does not match the pattern cannot be created at all, so the attribution is a property of the access rather than a convention GovIntel follows.
What a constant name would cost
You would be able to see that GovIntel acted, and nothing about which engagement or which run. For a product sold on auditability that is indefensible: activity in your account could not be reconciled against the assessments you commissioned.
How to use it
Filter your CloudTrail on the assumed-role session name. Every call the assessment made appears under it.
What it does not mean
The session name is not a credential and not a secret. It is an identifier, and it is meant to be read.
