Documentation Index
This directory contains the current user guides, implementation references, and
design records for the Amazon Connect Customer Posture Assessment Tool.
Table of Contents
Start Here
- Project README — installation, AWS access, common CLI usage, and report overview.
- User guide — detailed installation, AWS access, CLI usage, report operations, and CI/CD.
- Deployment architecture — rendered deployment diagram;
editable Draw.io source.
- Configuration guide — YAML/JSON settings, precedence, output naming, and execution tuning.
- Troubleshooting guide — installation, credentials, permissions, runtime, and report failures.
Current Behavior
- Check catalog — all 64 canonical controls, dispositions, methodology, executor ownership, aliases, and unified filter behavior.
- Report formats — HTML, JSON, CSV, and failed-control-only ASFF contracts, including the scored-control denominator.
- Performance guide — parallel execution, retry tuning, and journey-scoring bounds.
- IAM policy template — canonical read-oriented
List, Get, Describe, and Head permissions for the assessment; optional
S3 publishing writes are documented separately.
AWS Documentation
Contributors and Maintainers
- Development guide — setup, tests, code quality, architecture, and adding checks.
- Threat model — current trust boundaries, attack surfaces, and mitigations.
Design and Historical Reference
These documents describe design intent, decisions, or broader future capabilities. They
should not override the current behavior documented in the check catalog and
configuration guide.
Source-of-Truth Rules
- Runtime behavior: source code and tests.
- Canonical controls, aliases, disposition, and methodology:
checks/control_registry.py, checks/registration.py, and the
check catalog.
- Scoring:
score_policy.py. Only passed and failed CONTROL records enter
the scored-control denominator.
- Configuration keys and precedence: configuration guide.
- Required read permissions:
iam_permissions.py, IAM policy template, and the consistency tests.
- Design proposals: documents under
design/; they may describe capabilities not yet implemented.