ADR-014: AWS IAM Policy Entity Type — Introduce permission_set
Introduce type='permission_set' for AWS IAM Policies (and analogous policy-holder entities) rather than reusing type='role'
Introduce type='permission_set' for AWS IAM Policies (and analogous policy-holder entities) rather than reusing type='role'
Define the source_system tenancy scheme for AWS entities — account-scoped identifiers to support multi-account and multi-customer deployments
What SecurityV0 reads from your AWS account, what it never reads, and how you control and revoke access. The plain-English summary of the canonical IAM permission set.
High-level implementation plan and graph-enhancement research for a SecurityV0 AWS connector — covering IAM identity graph, workload metadata, ECR/code-deploy chain, and cross-account trust modelling
One-page demo narrative for the Nimbus Cloud AWS tenant. Maps the four canonical Sergey stories to the live UI surfaces operators see in the nimbus-cloud tenant.
Implementation cycle plan for shipping SecurityV0 AWS integration across sv0-connectors, sv0-platform, and documentation, based on the March AWS research and competitive analysis.
How Veza and major security platforms integrate with AWS multi-account environments — onboarding architectures, IAM patterns, cross-account hub models, and what SecurityV0 should learn from each.
Strategic plan for SecurityV0 AWS expansion beyond the connector itself: the most valuable workload-identity use cases, multi-account success path, Bedrock/agentic scope, and an IaC-first demo lab plan.
Comprehensive catalog of all AWS non-human identity types, their authentication mechanisms, SecurityV0 entity mappings, ownership decay scenarios, and discovery APIs.
AWS Organization structure, account inventory, and Terraform conventions for SecurityV0
Why SecurityV0's current resource identity model cannot support deterministic path-scoped execution evidence attribution, and a proposal to introduce a first-class canonical resource_key on both entities and evidence records.
Proposal for automating source system provisioning across Azure, AWS, GCP, and ServiceNow using Terraform modules for cloud identity and per-connector Python setup scripts for SaaS configuration
Honest per-connector accounting of how SecurityV0 derives execution counts, where those numbers match ground truth, and where they don't.
Infrastructure automation for SecurityV0 — dev environment provisioning, cloud identity setup, and source system configuration
MediaPro Lab 2 — multi-account AWS + ServiceNow + Entra + Foundry stitched-graph demo, full IaC up/scan/teardown lifecycle.
Per-tenant AWS connector that scans N accounts × M service categories independently, with role-chain auth and partial-failure isolation.
High-level plan for building realistic demo environments with live system data instead of synthetic metadata
SecurityV0 infrastructure strategy: AWS credits, connector automation, AWS Organization account structure, budget protection, demo lab environments, and phased migration plan from Hetzner.
Founder feedback on the first AWS demo. The use cases are strong, but the product is still surfacing path inventory instead of the canonical governance stories.