The Wired Connection faster Tour Updated iA live inventory of every AWS resource across the org, with security findings from Prowler (CIS, NIST 800-53, PCI-DSS, and AWS Foundational benchmarks). Rebuilt automatically by the nightly cloud audit. Leads only

Automation team · internal

Infrastructure

Every cloud resource in the AWS org — what it is, why it's here, who owns it, and its security posture. Findings come from Prowler run against the same CIS, NIST 800-53, PCI-DSS, and AWS Foundational benchmarks, scored and cited the same way as the automation audit.

How it all connects

Three dashboards, one flow. Hover to trace a path; click any box to see how it works inside.

contract PDFs extract + BAA AI review usage + cost inventory + Prowler live scan BAA status shared audit data Google Drive Contract PDFs Anthropic Claude Haiku + Sonnet AWS Org accounts + resources n8n + Tray Live automations Contract Renewals Supplier contracts + BAA registry S3 state + DynamoDB YOU ARE HERE Automation Inventory n8n + Tray workflows, scored + Infrastructure — AWS + Prowler audit dataset (S3) YOU ARE HERE Token Governance Every Claude key: usage, cost, rotation DynamoDB YOU ARE HERE One pane of glass unified, cross-linked view •  Contracts •  Automation •  Token Governance linked, not copied
data in shared between dashboards unified view
Inventory · live Prowler · CIS / NIST / PCI / AFSBP
How we score — and how we cut the noise

Findings come from Prowler, an open-source scanner that runs the same control benchmarks as AWS Security Hub (CIS, NIST 800-53, PCI-DSS, AWS Foundational). Raw Prowler is deliberately exhaustive — it flags every best-practice gap, including operational, cost, disaster-recovery, and compliance-niche items that are not security risks for this estate. We triage that in two layers so what you see is signal, not noise.

1 · Tuning policy. A documented allow/mute/downgrade policy removes checks that aren't security risks here (e.g. log-group CMK — logs are already encrypted by default; S3 MFA-delete — needs root, effectively unusable) and corrects Prowler's over-severe ratings. Nothing is deleted: every suppressed finding is shown with its reason under Tuned out.

2 · Adversarial AI review. Two opposing AI reviewers — one hunting false positives, one guarding against under-rating — adjudicate each check, and a per-resource pass asks "does this actually apply to this resource?" Findings judged false-positive or by-design are moved to Tuned out with the reasoning; the rest carry a review note you can read on each card. Confirmed-real findings are marked, and ones needing a live check are flagged.

Score. Every resource starts at 100; we subtract per active finding (Critical 40, High 28, Medium 14, Low 5), floored at 0. 85+ is Good, 70–84 Fair, 50–69 Watch, under 50 Risk.

ResourceTypeAccount RegionOwnerPHISecuritySign-off

Every scan is diffed against the previous one. Remediations and new issues are recorded here so a fix is never silently lost — a durable audit trail, kept in the same store as sign-offs.

← back to all tools