Cloud Accounts

On the [Tenant & Organization > Cloud Account] page, you can connect cloud service provider accounts and manage their credentials, collection status, and access configurations.

Metric Cards

Three summary cards are displayed at the top of the page:

CardDescription
Total AccountsTotal registered accounts, split by Root and General
Summary by ProviderDistribution bar chart across AWS, Azure, and Google Cloud
Collection IssuesCount of accounts with collection failures or cancellations

Viewing Cloud Accounts

Accounts are displayed in a paginated table. Use the tab bar above the table to filter by account scope:

TabDescription
All AccountsEvery registered cloud account
Root AccountParent accounts that manage permissions
General AccountsWorkload accounts (Direct or Delegated)

Each tab shows a badge with the current count.

Table Columns

ColumnDescription
NameAccount display name (alias)
Cloud Account IDProvider-specific identifier — AWS Account ID, Azure Subscription ID, or Google Cloud Project ID
ProviderCloud service provider (AWS, Azure, Google Cloud)
Access TypeRoot Account, Delegated, or Direct
Credential StatusCurrent credential validity — Valid, Invalid, Expired, or Unknown
Collection StatusLatest collection result — Pending, Running, Success, Failure, or Canceled
Last CollectedTimestamp of the most recent successful collection

Click any row to navigate to the account’s detail page.

Search and Filters

UI ElementDescription
SearchSearch by account name or Cloud Account ID
Filter (funnel icon)Filter by Credential Status and/or Collection Status. Each category has an “All” toggle and individual checkboxes
All ProviderFilter by provider (AWS, Azure, Google Cloud). Supports multi-select
More menu (⋮)Additional options: Set Display (column visibility and page size), Refresh

Filter Popover

Click [Filter] to open the filter popover with two tabs:

TabDescription
Credential StatusFilter by credential validity — All, Valid, Invalid, Expired, Unknown
Collection StatusFilter by collection result — All, Pending, Running, Success, Failure, Canceled

Provider Filter

Click [All Provider] to select one or more cloud providers — AWS, Google Cloud, or Azure.

Tab Filtering

Use the tab bar to filter accounts by scope. Each tab displays a count badge:

Account Detail

Clicking a row opens the detail page for that account. The header displays the account name, provider badge, access type badge, and creation date. A [Disconnect] button is available in the top-right corner.

Detail Metric Cards

Three metric cards summarize the account’s health:

CardDescription
Credential & IAM StatusCurrent validity of credentials and IAM permissions
Collection StatusLatest resource collection status across all resource types
Cost SummaryMonth-to-date cost with trend comparison against the previous month

Basic Info

The Basic Info card shows account properties. Account Name and Description support inline editing — click the edit icon, modify the value, and save.

FieldEditableDescription
Account NameYesDisplay name for the account
DescriptionYesFree-text description of the account’s purpose
Cloud Account IDNoProvider-specific account identifier
ProviderNoAWS, Azure, or Google Cloud
Access TypeNoRoot Account, Delegated, or Direct
ManagerNoAssigned account manager
TagsNoApplied tags displayed as badges

Credentials

The Credentials card displays the secret schema type and masked credential fields. Click [Update Credentials] to replace the stored credentials with new values.

ℹ️
Credential update is currently supported only for AWS accounts. For Azure and Google Cloud accounts, contact your administrator.

Attached General Accounts

For Root Account type accounts, an additional Attached General Accounts section appears below the Credentials card. It lists all general accounts linked to this root account in a searchable, filterable table.

ColumnDescription
NameGeneral account display name
Cloud Account IDProvider-specific identifier
ProviderCloud service provider
Access TypeDelegated or Direct
Credential StatusCredential validity of the attached account
Collection StatusLatest collection result of the attached account

Connecting an Account

Click [Connect Account]

Click the [+ Connect Account] button at the top right of the list page. You will be navigated to a multi-step wizard.

Select a Provider

Choose the cloud service provider — AWS, Azure, or Google Cloud. The stepper shows 4 steps: Provider → Account Info → Verify → Save.

Configure Account Info

Select the account type (General Account or Root Account), enter the Account ID, Account Name, and Description. For Root Accounts, configure credentials directly. For General Accounts, select a connection method (Delegated or Direct).

Verify and Save

Review the configuration, verify the connection, and save the account. It will appear in the account list once registration completes.

Bulk Register

Use the [Bulk Register] button to register multiple Delegated General Accounts at once based on a selected Root Account. The wizard guides you through 5 steps.

Select Root Account

Choose the Root Account that serves as the delegation basis. The selected Root Account’s provider automatically determines the candidate list and credential fields.

Click the dropdown to search and select a Root Account from the list.

ℹ️
If only one Root Account is registered, it is automatically selected.

Select Target Accounts

Browse and select the Delegated General Accounts to register. Accounts are listed with their availability status — only Selectable accounts can be checked.

Use the checkboxes to select individual accounts or use the header checkbox to select all on the current page. The status filter dropdown lets you narrow the list:

FilterDescription
AllShow all candidate accounts
SelectableAccounts available for registration (default)
DuplicateAccounts already registered
UnavailableAccounts that cannot be registered

ℹ️
You can select up to 100 accounts at a time. If the selectable count exceeds 100, narrow the results using search or filters.

Configure Credentials

Enter the credential details that will be applied identically to all selected accounts. For AWS, provide the Role Name and External ID.

FieldDescription
Role NameThe IAM Role name (the part after role/ in the Role ARN). CloudOps does not auto-create the role — you must pre-create it in AWS
External IDThe External ID configured in the IAM Role’s trust policy for assume-role

⚠️
CloudOps does not auto-create the AWS Role. You must pre-create the Role in each target account before proceeding. The Role Name and External ID are applied identically to all selected accounts.

Validation

CloudOps runs a connection test (STS AssumeRole) for each selected account. The result shows Passed or Failed with a reason for each account.

StatusDescription
PassedConnection test succeeded — the account will be registered
FailedConnection test failed — the account will not be registered. Check the Reason column for details
ℹ️
Provider, Root Account, credentials, and selection are locked while validation is in progress. Only accounts that pass validation will be registered in the next step.

Result

Review the registration results. A summary shows total selected, success, and failed counts. Use the Success and Failed tabs to inspect individual accounts.

Disconnecting an Account

Open the disconnect dialog

On the account detail page, click the [Disconnect] button in the top-right corner.

Confirm disconnection

Review the warning message, then check the confirmation checkbox: “I understand that this action is permanent and agree to disconnect the account.” Click [Disconnect] to proceed.

⚠️
Disconnecting a cloud account is permanent and cannot be recovered. Data retention for associated resources, costs, and collection history follows the system operation policy.
ℹ️
A Root Account with attached general accounts cannot be disconnected directly. Disconnect the attached general accounts first to proceed.
ℹ️
When no cloud accounts have been registered, the page shows an empty state with the message “No Cloud Accounts Found” and a prompt to create a new account.
v1.1.0