Triagic + AWS: ticket investigations over your cloud account, read-only
Ask about any AWS service the IAM policy allows: EC2, S3, Lambda, RDS, ECS, CloudTrail, IAM and the rest. Runs the AWS API server locked to read-only operations. Triagic connects to AWS from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of AWS.
What you can ask
- In AWS, find the log lines for the Lambda that handles webhook retries between 10:00 and 10:20
- Did the error rate in AWS for the API gateway change in the last six hours?
- Which alarms in AWS fired this week, and which are still in alarm?
- Show me the AWS deployment that was live when ticket 4819 was filed
- What is the dead-letter queue depth in AWS right now?
What the agent can do
Triagic exposes every tool the AWS server annotates as read-only, and nothing else. READ_OPERATIONS_ONLY=true, the same read-only action check as DynamoDB, across every AWS service the credential can reach.
Connect in three steps
- 1
Mint a read-only credential in AWS
Create a dedicated user or token that can only read. READ_OPERATIONS_ONLY=true, the same read-only action check as DynamoDB, across every AWS service the credential can reach.
- 2
Add it in the Triagic portal
Integrations, then Add shared data source, then AWS.
- AWS access key ID
- AWS secret access key
- Profile name: A profile in the `~/.aws/config` of the machine running Triagic: the name inside `[profile …]`. It is that machine's file, not the portal host's.
- Region
- 3
Let a desktop pick it up
Saving validates the shape of what you typed. The first desktop app to sync starts AWS locally and reports running or degraded with the error text.
Field-by-field setup, TLS options and the error table: AWS in the docs.
Read-only, by construction
READ_OPERATIONS_ONLY=true, the same read-only action check as DynamoDB, across every AWS service the credential can reach.
FAQ
- Can Triagic change anything in AWS?
- No. READ_OPERATIONS_ONLY=true, the same read-only action check as DynamoDB, across every AWS service the credential can reach. Give it a read-only credential as well, so the guarantee does not rest on one layer.
- What do I need to connect AWS?
- AWS access key ID, AWS secret access key, Profile name, Region. The desktop app on a member's machine starts the connection; the portal never holds a live process.
- Does AWS cost extra?
- No. Every connector is included in the seat price. Start a 14-day trial without a card.
Related integrations
- AWS CloudWatchRead CloudWatch logs, metrics, and alarms.
- AWS SQS / SNSInspect queues, topics, and message attributes.
- Azure MonitorQuery Log Analytics and Application Insights with KQL, and read metrics and the activity log.
- AzureAsk about any Azure service the service principal can read: compute, storage, SQL, Cosmos, AKS, App Service, Monitor and more. Runs the Azure MCP server read-only; Key Vault values are never exposed.
Try it on your own AWS
No card. Install the desktop app, connect AWS read-only, and triage a real ticket this afternoon.