Importing Accounts

Importing Account Basics

Guardrails makes it easy to import AWS accounts, Azure subscriptions, and GCP projects. All three types of accounts can be imported via the Console, Terraform, or even via a GraphQL API request. Do a thorough read of the appropriate integration guides. These contain additional steps that must be done prior to importing into Guardrails:

Ensure that the proper access permissions are in place in the child account or Guardrails won't be able to get very far with Discovery!

Guardrails Console

To import an account, navigate to Accounts in the left sidebar, then click the Actions dropdown and select Connect Account.

Accounts page with Actions dropdown showing Connect Account option

Select your cloud provider:

Cloud provider selection (AWS, Azure, GCP)

AWS

AWS supports importing individual accounts or entire AWS Organizations.

AWS Account: Import a single AWS account with cross-account IAM role access.

AWS Organization: Import your entire AWS Organization hierarchy, including all OUs and member accounts. Organizations import includes:

For detailed instructions, see:

AWS account type selection showing Account and Organization options

Azure

Azure supports importing subscriptions, tenants, management groups, and Active Directory.

Subscription

Import an individual Azure Subscription.

New Azure Subscription

Tenant

Import an Azure Tenant to manage multiple subscriptions.

New Azure Tenant

Management Group

Import an Azure Management Group hierarchy.

New Azure Management Group

Active Directory

Import Azure Active Directory for identity governance.

New Azure Subscription

For detailed instructions, see Import Azure Resources.

GCP

GCP supports importing individual projects or entire organizations.

Simple import

Import a GCP Project with basic configuration.

New GCP Project Simple

Advanced import

Import a GCP Project with advanced options.

New GCP Project Advanced

For detailed instructions, see: