Skip to main content

Accounts & provider groups

The Accounts page is the inventory of everything Argus scans. The connect wizard lists sixteen connectors, grouped into Cloud (IaaS), Container, SaaS / Identity, and IaC. AWS is the primary provider and the most complete today. Every connector has its own step-by-step guide, listed in Supported providers; AWS is covered in Connect an AWS account.

Search and filter​

Above the list, a search box and two filters narrow the accounts shown. They combine, and the page says how many accounts are showing out of the total.

  • Search matches an account's alias, its provider-native ID (AWS account ID, Azure subscription ID, Google Cloud project ID, cluster name, GitHub organization, and so on), and the provider's name or short name (aws, gcp, m365), ignoring case. Several words must all match: aws prod finds the AWS accounts whose alias contains "prod". Press / to jump to the search box and Esc to clear it.
  • Provider chips, one per provider type your workspace has connected, each with how many accounts it would show. Select several to see any of them.
  • Status narrows to Connected, Failed, or Checking accounts.

Organization groups show only their matching accounts, as "1 of 9 accounts", and a group with no match is hidden. The search and filters are kept in the page address, so a filtered view survives a reload and can be shared as a link. Clear resets them.

The account card​

Each connected account shows:

  • the auth method, such as assumed role, static keys, service principal, or AWS Organizations,
  • for an account registered through an AWS Organization, its organization unit (the OU path, or "Management account"),
  • the regions seen in the last scan,
  • the last scan and its outcome,
  • the connection state, which is Connected, Checking…, or Failed,
  • its open findings and posture score.

Lifecycle actions​

The card menu offers:

ActionWhat it does
Edit aliasrename the account's display name
Update credentialsreplace the stored secret and re-run the connection test
View scan jobsthe Scans list filtered to this account
Test connectionre-run the asynchronous connection check
Delete accountremove the connection, its credentials, and the account's scan history

Deleting an account removes the connection, its stored credentials, and the account's entire scan history, findings included. The deletion cannot be undone. The same account can be connected again later, starting from a clean history.

note

Credentials are stored server-side and never shown again after entry. For AWS role connections, the External ID is authored by Argus per workspace and cannot be edited. It is the isolation boundary that keeps the role usable only by its workspace.

Organizations​

Accounts registered through the AWS Organizations method (see Connect an AWS Organization) are grouped on the Accounts page under a header carrying the organization's name, its o-… id, and how many of its accounts are connected. Accounts that were connected on their own but belong to the organization join the group once it has been discovered. Accounts outside any organization are listed under Standalone accounts.

  • Sync organization on the header reads the organization again and offers the accounts that joined since the last sync, marked New. Accounts already connected are left as they are.
  • A provider group named after the organization is created when the organization is connected and extended on every sync, so the filters and scopes that already understand groups work for the organization too.
  • Each account remains an ordinary account: the card menu, connection test and deletion work exactly as for a single account.

Provider groups​

The Provider groups tab buckets accounts, production vs staging, per business unit, or per customer. The buckets scope and filter views across the console.

  • Create a group, then manage its membership from the connected accounts.
  • Groups are edit-anytime: membership changes take effect immediately in filters.
  • An account can belong to several groups.

Groups are the tool that gives severity context: a Critical finding in the production group and one in sandbox read very differently.

Plan limits​

Free connects 1 cloud account, Pro connects an unlimited number. The connect button reports the limit when it is reached. The cap is enforced server-side. The AWS Organizations method is shown to Free workspaces as a disabled card with the plan notice, since an organization always holds more than one account. See Billing & plans.