Connecting Kawach & AWS Accounts

AWS Logo

Overview

This article explains how to integrate AWS with Kawach to enable centralized compliance monitoring across your AWS environment. Once connected, Kawach can monitor AWS resources in read-only mode and surface relevant findings as part of your compliance and risk workflows.

This integration helps ensure that cloud infrastructure configurations, access controls, and operational signals are consistently tracked and available for audits, reviews, and internal assessments.

Prerequisites

Before starting the integration, ensure the following:

What Kawach Accesses

Kawach connects to AWS in read-only mode. It does not modify any configuration or resources in your AWS account.

Once connected, Kawach can:

Steps to Integrate AWS with Kawach

Step 1: Navigate to Integrations in Kawach

  1. Log in to your Kawach account.
  2. Go to Settings.
  3. Select the Integrations Tab.
  4. Click Create.
  5. Locate AWS from the list of available integrations.
  6. Click Connect.

Step 2: Authorize Kawach in AWS

  1. You will be redirected to the AWS IAM role creation flow.
  2. Follow the prompts to create a new IAM role for Kawach.
  3. Review the permissions requested by Kawach.
  4. Approve the role creation.
Note: You must have sufficient IAM permissions and AWS account admin approval to authorize the integration.

Step 3: Review and Confirm Permissions

After authorization:

  1. Review the attached read-only policies:
  2. SecurityAudit
  3. AWSCloudFormationReadOnlyAccess
  4. CloudWatchReadOnlyAccess
  5. Confirm the permissions.

Kawach will begin syncing data from your AWS account.

After the Integration

Once the integration is complete:

This setup supports ongoing compliance by ensuring cloud infrastructure evidence is consistently available.

Troubleshooting

Pin icon Authorization failed

Ensure you are logged into the correct AWS account and have permission to create IAM roles, with account admin approval.

Pin icon Resources not visible

Verify that the IAM role includes all required read-only policies.

Pin icon Data not syncing

Allow a few minutes after setup. If issues persist, try reconnecting the integration.