AWS · Cloud service
AWS CloudTrail with OrchestrAI
Catalog exported 2026-09-02
Turn on AWS CloudTrail and search API activity from chat: create trails, list them, and look up events.
OrchestrAI exposes 4 CloudTrail operations: 3 are low-risk (read-only or low-impact), and 1 create or modify resources and run only after you confirm the plan. 1 of them also carries a step-level approval gate.
What teams use it for
Security and compliance teams use OrchestrAI to confirm which trails exist in an account, create a new trail where logging is missing, and search recent API events by user, resource, or event name during an investigation. Listing trails and looking up events are low risk, while creating a trail waits for your confirmation. The coverage stops at creation and lookup, so stopping, updating, or deleting a trail is not available and must be done in the console.
Every CloudTrail operation, with its risk level
| Operation | What it does | Risk | Step-level approval |
|---|---|---|---|
Create CloudTrail Trail |
Create a CloudTrail trail for API activity logging | Low risk | No |
List CloudTrail Trails |
List CloudTrail trails | Low risk | No |
Lookup CloudTrail Events |
Lookup CloudTrail events | Low risk | No |
Create CloudTrail Trail |
Create CloudTrail trail | Creates resources | Yes |
Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.
Prompts that work
- List all CloudTrail trails in the account and tell me which regions are covered
- Create a multi-region CloudTrail trail called org-audit that writes to the audit-logs bucket
- Look up CloudTrail events for DeleteBucket calls in the last 24 hours
Before anything runs
Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.
Frequently asked questions
- Can OrchestrAI search CloudTrail events?
- Yes, the lookup_events operation searches recent management events by attributes such as event name, user, or resource. It is read-only and low risk.
- Will OrchestrAI create a CloudTrail trail without asking?
- No, creating a trail is medium risk with confirmation, so the plan, including the target S3 bucket, is shown to you before anything runs.
- Which CloudTrail operations need an extra approval step?
- One operation carries a step-level approval gate on top of plan confirmation: Create CloudTrail Trail. None of them is classed destructive.
Other AWS services
Related integrations
Try it on your own account
Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.
Unused credits refunded in your first 14 days.