AWS Cloud Governance Documentation

AWS Cloud Governance is a self-hosted, serverless AWS platform for event-driven automation and reversible containment. It maps your cloud inventory into a queryable graph, organizes CloudTrail activity by actor, and runs detection rules and runbooks that contain principals or remediate resources — every action reversible, with a full execution history — all inside your own AWS account with no data leaving your infrastructure. Amazon GuardDuty integration is available for teams that already run it.

What does it do?

  • Maps your cloud inventory into a queryable graph — filter in plain English and walk relationships between resources across accounts and regions.
  • Explores CloudTrail activity by actor with timelines, per-actor profiles and an activity graph for fast investigation.
  • Automates the response with detection templates, rules and runbooks — contain a principal, stop an instance, revoke a security-group rule — gated on inventory conditions and recorded in the execution history.
  • Keeps the undo button: every action is reversible where an inverse exists, with one-click rollback from a single unified Actions log.

Browse Documentation

🚀 New to AWS Cloud Governance?

Start with the Architecture page to understand how all AWS services connect, then read Automation to build your first detection rules and runbooks.