Where the workloads run, and where the audit trail lives.
AWS is where a large share of enterprise workloads and, increasingly, agent runtimes sit. Our work is the identity boundary, the audit trail, and the agent runtime alongside an Atlassian estate.
We build on AWS where the estate already runs there. The interesting parts for us are the identity boundary and the trail that proves what happened.
What it is
AWS is where a large share of enterprise workloads and, increasingly, agent runtimes sit. We build on it rather than resell it, usually because the estate we are governing already depends on it.
Our involvement concentrates on the parts that decide accountability: who can reach what, what that access is recorded as, and how an agent runtime is scoped when it starts acting on production systems.
Where it fits
AWS spans three layers. L1 is IAM Identity Center, the federation boundary that should be answering to the same directory as everything else. L2 is compute, containers, and data, the platform the work actually runs on. L3 is CloudTrail, the record of what was done and by which principal. L4 is Bedrock and AgentCore, where an agent gets a runtime and a set of permissions it did not previously have.
What we do with it
Federation to one directory
Identity Center pointed at the same identity provider as the rest of the estate, so access is granted and removed in one place.
Evidence and audit trail
Making sure the record of who did what is complete enough to answer a question months later.
Agent runtime scope
What an agent runtime may reach, decided before it is given credentials.
Ongoing operation
Access changes, reviews, and the drift that accumulates between projects.