Cloud Access Documentation
This page gives security, cloud, and procurement reviewers a concise overview of Hoogly's read-only cloud access model across all three products — Security, Compliance, and Cost Audit — and the downloadable review artifacts for each.
Review scope summary
Use this section for a fast understanding of how Hoogly requests access, what permission scope it needs, and how customers retain control.
What each product requires, and nothing more
Hoogly is three products — Security, Compliance, and Cost Audit. Security and Compliance share one read-only role; Cost Audit uses a second, separate role so its broader read scope is never bundled into the security connection.
160+ configuration checks
Uses the AWS-managed SecurityAudit policy plus a small inline HooglyExtraReadOnly policy for account-level metadata (credential report, region opt-in status, account summary) that SecurityAudit doesn't cover.
SOC 2, ISO 27001, HIPAA, PCI DSS, CIS
Requires no additional permissions. Compliance mapping is a scoring layer on top of the same read-only evidence the Security role already collects — nothing new is granted or connected.
FinOps & savings opportunities
Uses a dedicated HooglyCostRole, connected separately. Grants read-only Cost Explorer (ce:Get*), Compute Optimizer (compute-optimizer:Get*), CloudWatch metrics, and basic resource-inventory reads (EC2, RDS, Lambda, ASG, ELB) needed to size idle and over-provisioned resources.
Included review topics
The PDF and embedded preview follow the same structure so cloud, procurement, and security reviewers are working from the same source material.
Trust relationship and ExternalId usage
The documentation covers the trust relationship, trusted cloud account, and the ExternalId condition used to support cross-account access review.
Managed and inline IAM permissions, per role
Reviewers can inspect the managed and inline IAM permissions attached to each Hoogly role — the SecurityAudit baseline for Security/Compliance, and the separate Cost Explorer / Compute Optimizer policy for Cost Audit.
Direct cloud API operations used by the app
The artifact lists the direct cloud API operations used by the current application for scan validation and evidence-oriented reads.
Operational boundaries and reviewer checklist
The package includes operational boundaries, revocation guidance, and a reviewer checklist for internal approval workflows.
High-level role and evidence path
This sequence shows the customer-controlled access boundary from IAM role creation through read-only validation and documentation output.
Customer cloud Account
The customer controls the source account and decides whether to create the review role.
IAM Role with trust policy
A customer-created IAM role defines the trust relationship and the read-oriented permission boundary.
Hoogly assumes role using ExternalId
The application uses the customer-provided trust path and ExternalId condition to establish a temporary read-only session.
Read-only API evidence collection
The current app performs validation and evidence-oriented cloud API reads without changing customer configuration.
Documentation / validation output
Reviewers can validate access scope against the embedded PDF, downloadable artifact, and IAM template reference.
Primary areas reviewers typically inspect
These sections map the most common approval questions to the exact trust, permission, and operational details covered by the documentation set.
AssumeRole with ExternalId
The trust path is based on a customer-controlled IAM role with an ExternalId condition to support cross-account access review.
SecurityAudit for Security/Compliance, a separate policy for Cost
Security and Compliance run on cloud SecurityAudit plus focused read-only extras. Cost Audit is intentionally kept out of that role and uses its own Cost Explorer / Compute Optimizer / CloudWatch policy on a dedicated role.
Preview online or download for procurement review
Reviewers can inspect the document in-browser or download the same artifact for vendor assessment, ticketing, or offline approval workflows.
Direct cloud API validation visibility
The current application uses explicit cloud API calls to validate scanner prerequisites and read evidence-relevant configuration state.
Review the same artifact you can download
The embedded view below is the same documentation artifact available through the downloadable PDF, making it easier to review online before routing the file into procurement or security workflows.
If your browser blocks inline PDF rendering, use the fallback links here to download the file, open it in a new tab, or inspect the IAM template used by the current application.