Skip to content

Connect to AWS IAM Identity Center

Actagate sends the AWS account ID and permission set fixed in an approved request to AWS IAM Identity Center to create an account assignment. The requester is resolved to an Identity Center user using the email address synced from Slack. For requests with an expiry date, the same assignment is deleted automatically when it expires.

Requests and approvals also work without this connection. Grants and revocations then become runbook tasks for the responsible group.

Set these three values in the Bot and Web runtime environments. If any value is missing, the AWS integration is disabled and falls back to runbook tasks.

AWS_REGION=ap-northeast-1
ACTAGATE_AWS_SSO_INSTANCE_ARN=arn:aws:sso:::instance/ssoins-0123456789abcdef
ACTAGATE_AWS_IDENTITY_STORE_ID=d-0123456789

Check the values with this command:

aws sso-admin list-instances --region ap-northeast-1

Use the AWS SDK’s standard credential methods: an IAM role in the runtime environment, an AWS profile, or standard environment variables. You do not need to store permanent access keys in Actagate configuration files or the database.

Allow only the operations needed to grant access, check completion, and revoke access. Replace <INSTANCE_ID> and other placeholders with actual values. For multiple targets, add their ARNs to Resource. Only ListInstances requires * because it does not support resource-level restrictions.

{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ActagateIdentityCenterAssignments",
"Effect": "Allow",
"Action": ["sso:CreateAccountAssignment", "sso:DeleteAccountAssignment"],
"Resource": [
"arn:aws:sso:::instance/<INSTANCE_ID>",
"arn:aws:sso:::permissionSet/<INSTANCE_ID>/<PERMISSION_SET_ID>",
"arn:aws:sso:::account/<TARGET_ACCOUNT_ID>"
]
},
{
"Sid": "ActagateIdentityCenterStatus",
"Effect": "Allow",
"Action": [
"sso:DescribeAccountAssignmentCreationStatus",
"sso:DescribeAccountAssignmentDeletionStatus"
],
"Resource": "arn:aws:sso:::instance/<INSTANCE_ID>"
},
{
"Sid": "ActagateIdentityCenterPermissionSetRead",
"Effect": "Allow",
"Action": "sso:DescribePermissionSet",
"Resource": [
"arn:aws:sso:::instance/<INSTANCE_ID>",
"arn:aws:sso:::permissionSet/<INSTANCE_ID>/<PERMISSION_SET_ID>"
]
},
{
"Sid": "ActagateIdentityCenterDiscovery",
"Effect": "Allow",
"Action": "sso:ListInstances",
"Resource": "*"
},
{
"Sid": "ActagateIdentityStoreUserResolution",
"Effect": "Allow",
"Action": ["identitystore:GetUserId", "identitystore:ListUsers"],
"Resource": [
"arn:aws:identitystore::<IDENTITY_CENTER_ACCOUNT_ID>:identitystore/<IDENTITY_STORE_ID>",
"arn:aws:identitystore:::user/*"
]
}
]
}

After initial setup, you can remove sso:ListInstances and identitystore:ListUsers from the execution role.

Replace the “AWS account” and “Permission set” choices in the aws-access catalog with your organization’s actual values. You can change these in the catalog editor on the administration page. The requester’s email address must match an Identity Center user.

  1. Submit a request with a short expiry through aws-access and have it approved.
  2. Check that the assignment was created in the AWS Management Console and that one issued item with an expiry was recorded in the Actagate ledger. If the same assignment already exists, the request still succeeds and the record marks it as existing.
  3. When it expires, the assignment is deleted and the issued item in the ledger is marked as revoked. An assignment that has already been deleted is also recorded as a success.
  • The ledger records the exact assignment identifiers (account ID, permission set ARN, and user ID). Revocation uses only these identifiers.
  • If the user cannot be found or an API error occurs, only a fixed reason code is recorded. The email address and error message are omitted.