AWS Cloud Governance Documentation
AWS Cloud Governance is a self-hosted, serverless AWS platform for event-driven automation and reversible containment. It maps your cloud inventory into a queryable graph, organizes CloudTrail activity by actor, and runs detection rules and runbooks that contain principals or remediate resources — every action reversible, with a full execution history — all inside your own AWS account with no data leaving your infrastructure. Amazon GuardDuty integration is available for teams that already run it.
What does it do?
- Maps your cloud inventory into a queryable graph — filter in plain English and walk relationships between resources across accounts and regions.
- Explores CloudTrail activity by actor with timelines, per-actor profiles and an activity graph for fast investigation.
- Automates the response with detection templates, rules and runbooks — contain a principal, stop an instance, revoke a security-group rule — gated on inventory conditions and recorded in the execution history.
- Keeps the undo button: every action is reversible where an inverse exists, with one-click rollback from a single unified Actions log.
Browse Documentation
Dashboard
Security posture and recent activity at a glance.
Inventory
The queryable cloud resource graph.
Events
Actor-centric CloudTrail activity explorer.
Automation
Detection templates, rules, runbooks and executions.
Actions
Unified, reversible log of every action taken.
Accounts
Manage the AWS accounts you collect and act on.
Notifications
Route alerts to SNS, email, or webhooks.
Buckets
S3 anomaly detection settings.
Application
Stack settings and template updates.
Entities
Principals and the resources they touch.
License
License status, trials, and key management.
Architecture
How all services connect and data flows.
Cost Estimation
What it costs to run AWS Cloud Governance in AWS.
🚀 New to AWS Cloud Governance?
Start with the Architecture page to understand how all AWS services connect, then read Automation to build your first detection rules and runbooks.