Connect your AWS account
Set up a read-only IAM role so DevControl can analyse your costs, security posture, and infrastructure health.
Create the IAM role
In your AWS Console, create a new IAM role with the following trust policy. This gives DevControl read-only access to your account.
The role name must start with DevControlRole, for example DevControlRole or DevControlRole-Prod, and must not use an IAM path. DevControl cannot assume a role with any other name.
Attach the ReadOnlyAccess managed policy to this role.
Enter your Role ARN
After creating the role, paste the Role ARN below. Its name must start with DevControlRole, so it looks like: arn:aws:iam::123456789012:role/DevControlRole
What DevControl reads
- ✓EC2, RDS, Lambda, S3 resource metadata
- ✓CloudWatch metrics and alarms
- ✓Cost and usage reports
Read-only by default. Optional remediation actions require separate, explicit permission and your approval.
Security
- 🛡️AES-256 encrypted at rest
- 🛡️SOC 2 readiness planning underway
- 🛡️Role credentials never stored
Need help?
Our setup guide walks through the exact IAM role configuration step by step.
View setup guide →