Trust & data handling
Argus scans cloud accounts from the outside, with read-only credentials and nothing installed in the scanned environment. The claims behind that sentence are spread across the setup pages, so this page gathers them in one place. A workspace is the Argus tenant that owns the connected accounts, the scans and the findings.
What a connection grants
Argus reads an account's configuration through the cloud provider's own API and evaluates it against its checks. It never runs anything inside the account.
- Assumed role, the recommended AWS method. Argus assumes a role in the
scanned account and works with the short-lived session credentials that
returns, one hour by default. The role carries the two AWS-managed read-only
policies
SecurityAuditandViewOnlyAccess. Neither grants write access, so a scan cannot create, change or delete anything in the account. - Static keys, the fallback for accounts where creating a role is not possible. These are long-lived credentials that stay valid until they are rotated in the cloud account, which is why a role is the safer connection wherever one can be created.
- Revocation. Deleting the role, or rotating the keys, ends Argus's access to that account. There is no second way in.
When you connect an AWS Organization, each member account is still an ordinary
assumed role, the Argus scan role, carrying the same read-only policies
SecurityAudit and ViewOnlyAccess. The one addition is the
management-account role: alongside those read-only scan policies it holds read
access to the organization's structure (organizations:ListRoots,
organizations:ListOrganizationalUnitsForParent,
organizations:ListAccountsForParent), so Argus can discover the accounts to
offer you. The management account is itself scanned through that same role. No
part of the organization grants write access.
Setup for all three methods is covered in Connect an AWS account.
What Argus stores
A scan records what the account contains and how each check came out.
| Data | What it holds |
|---|---|
| Connected account | The provider, the account identifier, the alias set in the console, and the connection state |
| Resource inventory | Per resource, its native identifier, name, type, owning service, region and tags |
| Findings | Per evaluated check, the check identifier, severity, outcome, affected resource, the framework requirements it maps to, and when it was first and last seen |
| Scans | Start time, duration, what triggered the run, and the pass and fail counts |
| Mute rules | The name and reason given for a suppression, and the member who created it |
The inventory describes how a resource is configured. The contents of those resources, such as the objects inside a bucket, are not copied into Argus. Resource tags are stored as they are found, so a tag whose value is sensitive becomes readable by everyone in the workspace.
How credentials are held
- Credentials are written once. The console sends them when an account is connected and when its credentials are updated, and never reads them back. No screen displays a stored credential again.
- Update credentials replaces the stored secret and re-runs the connection test. The previous value cannot be recovered.
- The External ID is generated by Argus for the workspace and shown read-only in the connect wizard. Argus applies it to every credential write, so a role trust policy scoped to that External ID is usable only by the workspace it was issued to.
- Deleting a connected account deletes its stored credentials with it.
Who can read the results
- Every member of the workspace reads the same posture data. There is no per-account or per-member scoping of findings. See Team & roles.
- Each workspace is isolated from every other one. The workspace a request belongs to is taken from the signed-in session, never from anything the browser sends.
- Sign-in goes through Wazuh ID, the shared identity of the Wazuh Labs services. Argus holds no password of its own. See Sign in & activation.
- Removing a member ends their access to the workspace and leaves their Wazuh ID account intact.
Removing data
- Deleting a connected account takes its credentials, its scan history and its findings with it, irreversibly. Reconnecting the same account starts from an empty history. See Accounts & provider groups.
- Muting a finding deletes nothing. The finding stays in the data, marked as muted, and unmuting returns it to active posture. See Mute rules.
- Downgrading to Free deletes nothing. The plan limits re-apply at the end of the paid period. See Billing & plans.