# What this post explains
AWS provides a sample solution and planning guidance to automate governance for IAM Identity Center at scale. The goal is to maintain visibility into who can access which managed AWS applications, when they last accessed them, and to produce reports suitable for compliance and security reviews.
# Why you need continuous discovery and reporting
As organizations add more IAM Identity Center–integrated services and manage multiple AWS accounts and Regions, tracking access assignments becomes difficult. Manual or ad-hoc methods leave gaps in auditability and slow down responses to compliance requests. The sample solution identifies managed AWS applications and collects the user and group assignments for IAM Identity Center instances across an organization, then stores results in a queryable form and exports CSVs for downstream use.
# Planning the integration: four concrete areas
1) Who can provision managed AWS applications
- Keep creation of sensitive resources restricted using standard AWS controls: IAM policies, service control policies (SCPs), resource control policies (RCPs), or IaC policy evaluation tools (for example, OPA or Checkov).
- Apply the same provisioning guardrails you use for other AWS resources so only approved principals or pipelines can create managed application instances.
2) Who manages user and group assignments
- Define clear responsibilities: a managed application administrator should handle authorization within the account.
- Separate workflows: use an IaC pipeline for provisioning resources and a distinct workflow (self-service or ticketed) for membership changes.
- Users authenticate to Identity Center through your external identity provider (IdP). Identity Center then authorizes access to the managed AWS application and downstream AWS service resources.
4) How IdP identities map to AWS resource access
- Document and maintain the linkage between IdP users/groups, Identity Center application assignments, and downstream permissions.
- Consider using Identity Center features such as trusted identity propagation (TIP) when available to create end-to-end identity trails into downstream services.
# How the sample solution helps
- It enumerates IAM Identity Center instances within an AWS Organization and discovers associated managed applications and their assignments.
- The output is stored in a queryable format to support ad-hoc queries and automated checks.
- It produces CSV files that can be consumed by compliance teams, security reviews, or reporting pipelines.
# Operational recommendations
- Enable delegated administration for Identity Center over your Organization instances so member accounts can manage resources under controlled delegation.
- Ensure the IAM principal that provisions an application has both: (a) the service-specific IAM permissions needed to create the AWS resource, and (b) the sso permissions needed to manage Identity Center application instances (CreateManagedApplicationInstance, GetManagedApplicationInstance, DeleteManagedApplicationInstance, DescribeRegisteredRegions, etc.).
- Integrate the discovery reports into your audit and ticketing systems to automate evidence collection for reviews.
# Typical governance questions this solves
- Which users or groups have access to which AWS applications?
- Who last accessed a given AWS application and when?
- Which users and groups are assigned across accounts and Regions?
- How to quickly produce CSV-based reports for audits.
# Bottom line
The combination of planning (who provisions and who manages assignments), using Identity Center features like TIP, and running an automated discovery-and-reporting pipeline gives you a repeatable, queryable way to answer access and audit questions across an AWS Organization.