Skip to content

Choose an execution connection

Organization administrators choose the cloud connection used for work after approval. Use this page to decide which permissions to delegate and which tasks people will complete manually.

Requests and approvals work without a cloud connection. If automated grants or revocations are unconfigured or fail, the work becomes a manual runbook task for the responsible group. A member performs the work externally and records completion with evidence.

Cloud operation runbooks use copy mode when no account is registered, signing keys are missing, or an operation is not allowed. The operator runs the displayed command in their own environment and records the result. A failed connection test is not treated as success.

  1. Identify the work to automate and choose a page below. You will have a connection method and a defined task.

    Cloud Authentication for cloud operations Instructions
    AWS OIDC AssumeRoleWithWebIdentity, or AssumeRole with an external ID AWS
    Google Cloud Workload Identity Federation with service account impersonation Google Cloud
    Azure Federated credentials on an Entra ID app Azure
  2. For automated access grants, also read “What gets executed” on that page. AWS Identity Center, Google Workspace, and Entra ID grant executors have separate configuration from cloud account registration. This tells you what registration alone enables.

OIDC lets your cloud trust the Actagate issuer and issue temporary credentials. The issuer URL is OIDC_ISSUER_BASE_URL with trailing / characters removed, followed by /t/<organization ID>. The subject is org:<organization ID>:account:<key>. Copy the values from the settings screen exactly.

The deployment operator must configure OIDC_ISSUER_BASE_URL and OIDC_SIGNING_KEYS for OIDC. Customers do not paste signing keys into the registration form.

  1. Create a dedicated role, service account, or app in your cloud. Limit permissions to the target resources and selected operations. Do not use broad roles such as OrganizationAccountAccessRole. You will have a defined permission boundary for the connection.
  2. For AWS and Google Cloud, optionally configure a separate read identity. Without it, reads use the execution configuration. This determines the permissions used for checks before and after changes.
  3. Select the required “Allowed operations.” This list does not grant IAM or RBAC permissions in your cloud. Steps using an unselected operation fall back to copy mode. You now have a defined set of operations for automatic execution.
Cloud accounts
Manage connections in Cloud accounts.
  1. In settings, open “Cloud accounts,” click “Add account,” and follow the cloud’s instructions. “Account saved.” appears and the connection joins the list.
  2. After saving, click “Test connection.” The borrowed identity and “Expires at” appear. The test checks authentication; it does not prove permission for every operation.
  3. Check the audit log for cloud_account.created, cloud_account.updated, cloud_account.deleted, and cloud_account.connection_tested. Registration, changes, deletion, and tests record the account key and success or failure. Tokens and secret credentials obtained during tests are not recorded.

[Screen: cloud account registration form]

[Screen: cloud account connection test result]

If saving fails, check input formats, duplicate keys within the organization, and issuer configuration. The form does not accept access keys, service account key JSON, or client secrets.

Operators complete work that cannot run automatically through manual runbook tasks or copy mode. Send the on-screen message and account key to your organization’s administrator or deployment operator for diagnosis.