forumNew topic

Client's auditor wants us to create an 'AWS security audit role' in our cloud account — how much permission should we grant?

ZZehra B***ExpertCommunity member
Joined
Jan 2025
Message
379
#1

We are a 7-person healthtech software company operating in the US market. We're at the contract signing stage with an enterprise client for an annual value of $45,000. However, the client's third-party auditing firm has requested that we configure an AWS security audit role in our root/primary cloud account for compliance checks.

Our systems store sensitive patient data and proprietary algorithms. They sent over a doc requesting a specific role template, but we aren't completely sure which exact permissions to open up. We don't want to over-privilege and risk our data and infrastructure, but we're also worried about failing the audit if we lock it down too much.

What is the standard, secure procedure for this kind of external audit? Which built-in permission policies should be used how should the auditor's access duration be limited, and how should their actions be audited/logged?

VVolkan A***Veteran
Job title
Software Architect
Joined
Apr 2023
Message
312
Most Helpful#2

Short answer: The client's auditor should only be assigned read-only security policies, with absolutely no direct access to production data. Instead of a permanent user, you must set up an assumed role requiring an external ID for third-party auditing.

Never grant general read-only access to auditors. The managed policy provided by AWS called SecurityAudit is specifically designed for reviewing system security configurations, encryption settings, and network rules. This policy reads infrastructure setups but doesn't grant permissions to view the contents of storage buckets or rows in database tables. The auditor needs to see how the system is architected, not your client data inside it.

When setting up access, do not create an IAM user and hand over a password or access keys. Instead, create a cross-account role targeting the other party's AWS account ID. Always include a complex external ID (ExternalId) condition in the trust policy and cap the max session duration at two hours. That way, the role can only be assumed using temporary credentials during active audit sessions.

Lastly, before handing over the role, ensure account-wide CloudTrail logging is enabled and validated. Every API call made by the auditor should be captured in this trail, with log file validation turned on to prevent tampering. Once the audit is over, simply delete the trust relationship to revoke access completely.

YYavuz G***Member
Job title
Courier coordinator
Sector
Packaging
Organization type
family business
Joined
Jun 2025
Message
45

Doki · Log management setup · 2023

#3

The key distinction here is ReadOnlyAccess vs. SecurityAudit. If you attach ReadOnlyAccess, the auditor can download files from your object storage and snoop around database metadata way too much. A security auditor only needs the SecurityAudit policy and maybe a few scoped-down monitoring dashboards if requested.

ÖÖmer Ö***Member
Job title
Social media manager
Sector
Printing
Organization type
chain store
Joined
Feb 2023
Message
64
#4

Don't skip these three steps for a secure audit role: 1) Add an unguessable, random ExternalId condition to the trust policy. 2) Set the role's MaxSessionDuration to one hour. 3) Restrict the role to their specific office IP block using an IP address condition in the policy.

YYasemin Ö***MemberCommunity member
Joined
Apr 2023
Message
20
#5

Very few audit frameworks actually require an external auditor to log into a live AWS account directly. Most of the time, exported configuration reports and CLI dumps are plenty. Have you asked them in writing why they can't just accept configuration reports before letting them into the account?

Correction: I misremembered the figure, it was a bit lower.

JJale S***ExpertCommunity member
Joined
Dec 2024
Message
151
#6

A bilateral NDA must be signed with the auditing firm before provisioning any access. The scope of the audit, targeted resources, and session logging liabilities must be clearly spelled out. No account credentials or roles should be shared before the legal baseline is sorted out.

SSelin U***MemberCommunity member
Joined
Mar 2026
Message
2
#7

We went through two similar audits last year. We only kept the role active for a 72-hour window and capped the session duration at 3 hours. The auditor ended up running just 42 unique API calls, got their data, and wrapped up. We deleted the role right after the window closed, zero headaches.

ÖÖzgür Y***Member
Job title
IT Manager
Sector
Chemistry
Organization type
boutique agency
Joined
Nov 2023
Message
5

Doki · Mobile app · 2025

#8

totally normal to panic a bit the frst time this comes up then don't worry, if you tell their auditor "per our internal security policy we cannot provision direct console users but we can set up an audit role with an external ID," you'll actually come across as very professional.

ÜÜlkü S***MemberCommunity member
Joined
Oct 2024
Message
118
#9

once you set up the role filter by the role name in cloudtrail every now and then to see what theyre up to. I mean if they start poking around random services just call them out on it.

GGürkan A***Member
Job title
Studio Founder
Sector
Software
Organization type
chain store
Joined
Jul 2024
Message
139
#10

Don't waste time overthinking it: go to IAM, create a new role select another AWS account enter their account ID check the box to require an external ID, attach only the SecurityAudit policy, and save.

ZZafer Y***ExpertCommunity member
Joined
Jan 2025
Message
7
#11

Let me share my experience. The real issue isn't the number, but what it's based on.

I'm also curious if anyone does it differently.

KKemal P***New member
Job title
Software developer
Sector
Freight
Organization type
120-person company
Joined
Sep 2026
Message
79
#12

Looking at it as a process, the picture changes. When you try to change everything at once, nothing settles.

That's all, sorry if I went on too long.

LLeyla K***Expert
Job title
Store associate
Sector
Energy
Organization type
20-person company
Joined
Dec 2024
Message
29
#13

There's also a measurement aspect to this. An automated scan report is not the same as a penetration test.

I'm also curious if anyone does it differently.

VVolkan A***Veteran
Job title
Digital marketing specialist
Sector
Packaging
Organization type
chain store
Joined
Jan 2023
Message
191
#14

You're right.

YYağmur C***VeteranCommunity member
Joined
May 2023
Message
395
#15

If you're going this route, sort this out first. Just because everyone does it doesn't mean it's right.

Payment information changes are never verified through the channel they came from. I'm also curious if anyone does it differently.

FFeritMember
Job title
Car dealership
Organization type
8-person team
Joined
Jun 2024
Message
72
#16

You're right, I've been down that road too. Forgotten test environments are more often the entry point than live systems.

KKader A***Member
Job title
Customer service representative
Sector
E-commerce
Organization type
regional distributor
Joined
Dec 2025
Message
1

Doki · Corporate website · 2024

#17

My perspective changed after experiencing that. Processes without records never improve, because you don't know what to fix.

An automated scan report is not the same as a penetration test. Proven by experience.

OOkan F***Expert
Job title
Fintech product manager
Organization type
chain store
Joined
Aug 2023
Message
146
#18

I didn't know that.

OOkan B***MemberCommunity member
Joined
Dec 2025
Message
134
#19

I went through the same thing.

FFatih K***MemberCommunity member
Joined
Jun 2025
Message
61
#20

Let me clarify the technical side. Most time waste accumulates in tasks waiting for approval.

Of course, it varies if your situation is different.

Reply