Security Documentation

Cloud Access Documentation

This page gives security, cloud, and procurement reviewers a concise overview of Hoogly's read-only cloud access model across all three products — Security, Compliance, and Cost Audit — and the downloadable review artifacts for each.

Version 1.0
Last updated July 05, 2026
Review type Security / Procurement
Access type Read-only

Review scope summary

Use this section for a fast understanding of how Hoogly requests access, what permission scope it needs, and how customers retain control.

Trust model
AssumeRole with ExternalId protects the trust path between the customer account and Hoogly.
Permission scope
Security and Compliance run on the SecurityAudit baseline plus scoped read-only additions. Cost Audit is a separate role scoped to Cost Explorer, Compute Optimizer, and CloudWatch metrics.
API behavior
The application performs read-only validation calls to confirm state and gather evidence context.
Revocation
Customers can revoke role access anytime by removing or disabling the IAM trust path.

What each product requires, and nothing more

Hoogly is three products — Security, Compliance, and Cost Audit. Security and Compliance share one read-only role; Cost Audit uses a second, separate role so its broader read scope is never bundled into the security connection.

Security

160+ configuration checks

Uses the AWS-managed SecurityAudit policy plus a small inline HooglyExtraReadOnly policy for account-level metadata (credential report, region opt-in status, account summary) that SecurityAudit doesn't cover.

RoleHooglyAuditRole
SetupOne CloudFormation stack
Write accessNone
Compliance

SOC 2, ISO 27001, HIPAA, PCI DSS, CIS

Requires no additional permissions. Compliance mapping is a scoring layer on top of the same read-only evidence the Security role already collects — nothing new is granted or connected.

RoleSame as Security
Extra accessNone
OutputAuditor-ready PDF
Cost Audit

FinOps & savings opportunities

Uses a dedicated HooglyCostRole, connected separately. Grants read-only Cost Explorer (ce:Get*), Compute Optimizer (compute-optimizer:Get*), CloudWatch metrics, and basic resource-inventory reads (EC2, RDS, Lambda, ASG, ELB) needed to size idle and over-provisioned resources.

RoleHooglyCostRole (separate)
SetupSeparate CloudFormation stack
Write accessNone

Included review topics

The PDF and embedded preview follow the same structure so cloud, procurement, and security reviewers are working from the same source material.

01

Trust relationship and ExternalId usage

The documentation covers the trust relationship, trusted cloud account, and the ExternalId condition used to support cross-account access review.

02

Managed and inline IAM permissions, per role

Reviewers can inspect the managed and inline IAM permissions attached to each Hoogly role — the SecurityAudit baseline for Security/Compliance, and the separate Cost Explorer / Compute Optimizer policy for Cost Audit.

03

Direct cloud API operations used by the app

The artifact lists the direct cloud API operations used by the current application for scan validation and evidence-oriented reads.

04

Operational boundaries and reviewer checklist

The package includes operational boundaries, revocation guidance, and a reviewer checklist for internal approval workflows.

High-level role and evidence path

This sequence shows the customer-controlled access boundary from IAM role creation through read-only validation and documentation output.

Step 1

Customer cloud Account

The customer controls the source account and decides whether to create the review role.

Step 2

IAM Role with trust policy

A customer-created IAM role defines the trust relationship and the read-oriented permission boundary.

Step 3

Hoogly assumes role using ExternalId

The application uses the customer-provided trust path and ExternalId condition to establish a temporary read-only session.

Step 4

Read-only API evidence collection

The current app performs validation and evidence-oriented cloud API reads without changing customer configuration.

Step 5

Documentation / validation output

Reviewers can validate access scope against the embedded PDF, downloadable artifact, and IAM template reference.

Primary areas reviewers typically inspect

These sections map the most common approval questions to the exact trust, permission, and operational details covered by the documentation set.

Trust Model

AssumeRole with ExternalId

The trust path is based on a customer-controlled IAM role with an ExternalId condition to support cross-account access review.

Policy Basis

SecurityAudit for Security/Compliance, a separate policy for Cost

Security and Compliance run on cloud SecurityAudit plus focused read-only extras. Cost Audit is intentionally kept out of that role and uses its own Cost Explorer / Compute Optimizer / CloudWatch policy on a dedicated role.

Reader Access

Preview online or download for procurement review

Reviewers can inspect the document in-browser or download the same artifact for vendor assessment, ticketing, or offline approval workflows.

Validation Scope

Direct cloud API validation visibility

The current application uses explicit cloud API calls to validate scanner prerequisites and read evidence-relevant configuration state.

Review the same artifact you can download

The embedded view below is the same documentation artifact available through the downloadable PDF, making it easier to review online before routing the file into procurement or security workflows.

Same artifact as downloadable PDF

If your browser blocks inline PDF rendering, use the fallback links here to download the file, open it in a new tab, or inspect the IAM template used by the current application.