Dasnuve · Cloud Discovery

Scrivas — AWS Organizations Assessment

Delegated administration, trust policies & trusted access · read-only enumeration
org o-qfj0pvhhv7
mgmt 716468089330
as iam/louis · 2026-08-19
2
Accounts in org
Scrivas Admin · Lazka — no OUs (flat)
6
Trusted access services
CloudTrail, GuardDuty, SecurityHub, Inspector…
0
Delegated administrators
Security ops run from the mgmt account
2
Third-party cross-account trusts
Intruder.io · Secureframe (both ExternalId-gated)
01

Trusted access services

org-enabled service principals
cloudtrail securityhub guardduty malware-protection.guardduty inspector2 notifications

Org-wide security tooling has trusted access enabled — Scrivas has begun centralizing security. on track

02

Delegated administrators

list_delegated_administrators
0

No delegated administrator is set despite trusted access being enabled for GuardDuty, Security Hub and Inspector. These services are therefore administered directly from the management account. Best practice is to delegate them to a dedicated security/audit account and keep the management account minimal. headline gap

03

Trust policies

org resource policy + IAM role trust relationships

Organization resource policy: none set. Of 44 IAM roles in the management account, all but three are AWS service / service-linked roles. Notable external & federated trusts:

IntruderReadOnlyRole 123311413059:root ExternalId Intruder.io — vulnerability scanning
SecureframeRole-f983f1e89008 728997465891:root ExternalId Secureframe — SOC 2 / compliance
AmazonEKS_EBS_CSI_DriverRole oidc.eks.us-east-2 federated EKS OIDC (IRSA)

Lazka member account (6 roles): only default service-linked roles + OrganizationAccountAccessRoleno GuardDuty/SecurityHub/Inspector roles, so org security services are not deployed into the member account.

04

Governance signals for the proposal

SeverityObservationWhy it matters
High No delegated administrators despite trusted access Security ops run from the mgmt account; violates multi-account best practice
High Workloads in the management account — EKS, EC2, RDS, VPC flow logs Blast-radius & separation-of-duties risk; mgmt account should be minimal
Medium Member account not monitored — Lazka lacks security SLRs Coverage gap; trusted access enabled but not delivered to members
Medium Flat org, no OUs — SCPs enabled but unused for targeting No policy boundaries; governance won't scale as accounts are added
Signal Compliance stack present — Intruder, Secureframe, Macie, Config, Access Analyzer Client is actively pursuing compliance — receptive to a landing-zone engagement