OrchestrAI Live

AWS · Cloud service

AWS CloudTrail with OrchestrAI

Catalog exported 2026-09-02

Turn on AWS CloudTrail and search API activity from chat: create trails, list them, and look up events.

OrchestrAI exposes 4 CloudTrail operations: 3 are low-risk (read-only or low-impact), and 1 create or modify resources and run only after you confirm the plan. 1 of them also carries a step-level approval gate.

4operations
3low risk
1create or modify
0destructive
1step-level approval

What teams use it for

Security and compliance teams use OrchestrAI to confirm which trails exist in an account, create a new trail where logging is missing, and search recent API events by user, resource, or event name during an investigation. Listing trails and looking up events are low risk, while creating a trail waits for your confirmation. The coverage stops at creation and lookup, so stopping, updating, or deleting a trail is not available and must be done in the console.

Every CloudTrail operation, with its risk level

AWS CloudTrail operations available through OrchestrAI
Operation What it does Risk Step-level approval
Create CloudTrail Trail Create a CloudTrail trail for API activity logging Low risk No
List CloudTrail Trails List CloudTrail trails Low risk No
Lookup CloudTrail Events Lookup CloudTrail events Low risk No
Create CloudTrail Trail Create CloudTrail trail Creates resources Yes

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

Prompts that work

  • List all CloudTrail trails in the account and tell me which regions are covered
  • Create a multi-region CloudTrail trail called org-audit that writes to the audit-logs bucket
  • Look up CloudTrail events for DeleteBucket calls in the last 24 hours

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Can OrchestrAI search CloudTrail events?
Yes, the lookup_events operation searches recent management events by attributes such as event name, user, or resource. It is read-only and low risk.
Will OrchestrAI create a CloudTrail trail without asking?
No, creating a trail is medium risk with confirmation, so the plan, including the target S3 bucket, is shown to you before anything runs.
Which CloudTrail operations need an extra approval step?
One operation carries a step-level approval gate on top of plan confirmation: Create CloudTrail Trail. None of them is classed destructive.

Other AWS services

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.