Skip to content

Connect a cloud account ​

Connect your own AWS, Azure, or GCP account to let Hashiro inspect its configuration. You need permission to manage cloud connections in your organization and permission to create a read-only scanning identity in the cloud account.

Open the connection form ​

  1. Open Cloud Security in the sidebar.
  2. Use the account connection action to open the form.
  3. Select AWS, Azure, or GCP.
  4. Fill in the account identifiers and credentials below.
  5. Click Connect and check the result.

Cloud account connection

Screenshots use fictional demonstration data.

A successful connection does not mean a security assessment has completed. Check the latest assessment time and results separately.

AWS ​

The current connection form accepts:

FieldValue
Account IDThe 12-digit AWS account identifier
Access Key IDAccess key for the scanning identity
Secret Access KeySecret paired with that key
RegionsComma-separated regions to assess, when specified

Create a dedicated IAM identity for read-only security inspection. AWS provides a SecurityAudit managed policy for configuration inspection. The exact required read permissions depend on the services assessed; ask your cloud administrator to review the scanner's requirements rather than granting unrestricted write access.

Generate an access key, copy its ID and secret into the form, and keep the secret in your organization's secret-management system. The visible form does not provide a role-ARN setup wizard. Role-based scanning configuration, when used, is handled through the appropriate administrative setup.

Azure ​

Create an application and service principal in Microsoft Entra ID. Assign the appropriate read access on the subscription, such as the Azure Reader role for resource inspection, with additional security read permissions only when needed. See Azure built-in roles.

The form requires:

FieldValue
Tenant IDDirectory identifier
Subscription IDSubscription being assessed
Client ID (App ID)Registered application's identifier
Client SecretSecret value, not the secret's identifier

Record the expiry date and rotate the secret before it expires. Use the subscription where the service principal has been granted access.

GCP ​

Create a dedicated service account in the project to assess and grant the read permissions required for resource and security configuration inspection. Review Google Cloud IAM roles for the relevant services.

The form requires Project ID and the service-account JSON key. Paste the complete JSON object. If your organization prohibits service-account key creation, coordinate an approved setup with your cloud administrator. Follow Google's key-management guidance.

Validate and manage the connection ​

From the connected-account list, open the account's action menu and choose Revalidate after rotating credentials or changing permissions. Check the resulting connection state and validation timestamp. The menu can also remove a connection where your permissions allow it.

Troubleshooting ​

SymptomWhat to check
Invalid credentialsCorrect account identifiers, key/secret pairing, and expiry
Access deniedRead permissions on the exact account, subscription, or project
No assessment resultsA connection can exist before the first completed assessment
Revalidation fails after rotationUpdate the stored connection credentials through the available management workflow
Cloud action unavailableOrganization license and cloud-management permissions

Credentials are encrypted at rest and are not returned in ordinary user-facing connection details. Do not place them in issue descriptions, public links, or project reports.

Hashiro. Continuous Threat Exposure Management.