Teams running an AWS Organization
Every new account is a new blind spot, and nobody remembers to onboard it.
One stack in the management account. A service-managed StackSet with auto-deployment puts the audit role in every member account, including the ones created next month.
The role name is fixed, so every member account’s role ARN is derived rather than configured. We enumerate the organisation from the management account and assume the same role name in each. An account created later is covered on placement and scanned on the next run — no one has to remember anything.
Without an AWS Config recorder, most Security Hub controls emit nothing rather than failing, and only around 211 of the 638 checks survive. We will not publish a score from an account that cannot support one — we name the resource types that are missing instead of reporting a confident number over an unstated subset.
Of our 117 rules, 11 overlap a Security Hub control, and each declares it so the two collapse to one unit of signal. They still earn their place: an account with no recorder gets nothing from Security Hub, and a rule reading the control plane directly still answers.