Accounts & provider groups
The Accounts page is the inventory of everything Argus scans. The connect wizard lists sixteen connectors, grouped into Cloud (IaaS), Container, SaaS / Identity, and IaC. AWS is the primary provider and the most complete today. Every connector has its own step-by-step guide, listed in Supported providers; AWS is covered in Connect an AWS account.
Search and filter
Above the list, a search box and two filters narrow the accounts shown. They combine, and the page says how many accounts are showing out of the total.
- Search matches an account's alias, its provider-native ID (AWS account
ID, Azure subscription ID, Google Cloud project ID, cluster name, GitHub
organization, and so on), and the provider's name or short name (
aws,gcp,m365), ignoring case. Several words must all match:aws prodfinds the AWS accounts whose alias contains "prod". Press/to jump to the search box andEscto clear it. - Provider chips, one per provider type your workspace has connected, each with how many accounts it would show. Select several to see any of them.
- Status narrows to Connected, Failed, or Checking accounts.
Organization groups show only their matching accounts, as "1 of 9 accounts", and a group with no match is hidden. The search and filters are kept in the page address, so a filtered view survives a reload and can be shared as a link. Clear resets them.
The account card
Each connected account shows:
- the auth method, such as assumed role, static keys, service principal, or AWS Organizations,
- for an account registered through an AWS Organization, its organization unit (the OU path, or "Management account"),
- the regions seen in the last scan,
- the last scan and its outcome,
- the connection state, which is Connected, Checking…, or Failed,
- its open findings and posture score.
Lifecycle actions
The card menu offers:
| Action | What it does |
|---|---|
| Edit alias | rename the account's display name |
| Update credentials | replace the stored secret and re-run the connection test |
| View scan jobs | the Scans list filtered to this account |
| Test connection | re-run the asynchronous connection check |
| Delete account | remove the connection, its credentials, and the account's scan history |
Deleting an account removes the connection, its stored credentials, and the account's entire scan history, findings included. The deletion cannot be undone. The same account can be connected again later, starting from a clean history.
Credentials are stored server-side and never shown again after entry. For AWS role connections, the External ID is authored by Argus per workspace and cannot be edited. It is the isolation boundary that keeps the role usable only by its workspace.
Organizations
Accounts registered through the AWS Organizations method (see
Connect an AWS Organization)
are grouped on the Accounts page under a header carrying the organization's
name, its o-… id, and how many of its accounts are connected. Accounts
that were connected on their own but belong to the organization join the
group once it has been discovered. Accounts outside any organization are
listed under Standalone accounts.
- Sync organization on the header reads the organization again and offers the accounts that joined since the last sync, marked New. Accounts already connected are left as they are.
- A provider group named after the organization is created when the organization is connected and extended on every sync, so the filters and scopes that already understand groups work for the organization too.
- Each account remains an ordinary account: the card menu, connection test and deletion work exactly as for a single account.
Provider groups
The Provider groups tab buckets accounts, production vs staging, per business unit, or per customer. The buckets scope and filter views across the console.
- Create a group, then manage its membership from the connected accounts.
- Groups are edit-anytime: membership changes take effect immediately in filters.
- An account can belong to several groups.
Groups are the tool that gives severity context: a Critical finding in the
production group and one in sandbox read very differently.
Plan limits
Free connects 1 cloud account, Pro connects an unlimited number. The connect button reports the limit when it is reached. The cap is enforced server-side. The AWS Organizations method is shown to Free workspaces as a disabled card with the plan notice, since an organization always holds more than one account. See Billing & plans.