AWS · Cloud service
AWS Config with OrchestrAI
Catalog exported 2026-09-02
Run AWS Config from chat: set up the recorder, add rules, and check compliance status by resource.
OrchestrAI exposes 4 AWS Config operations: 3 are low-risk (read-only or low-impact), and 1 create or modify resources and run only after you confirm the plan. 1 of them also carries a step-level approval gate.
What teams use it for
Compliance teams use OrchestrAI to check which Config rules are active in an account, see which resources are non-compliant, and add managed or custom rules such as encrypted-volumes or restricted-ssh. Listing rules and reading compliance are low risk; creating or updating a rule waits for confirmation. There is no remediation configuration operation, and rules cannot be deleted, so fixing a non-compliant resource or retiring a rule still requires the console or another service.
Every AWS Config operation, with its risk level
| Operation | What it does | Risk | Step-level approval |
|---|---|---|---|
Create Config Configuration Recorder |
Create an AWS Config configuration recorder for compliance tracking | Low risk | No |
Get AWS Config Compliance |
Get AWS Config compliance status | Low risk | No |
List AWS Config Rules |
List AWS Config rules | Low risk | No |
Create AWS Config Rule |
Create or update AWS Config rule | Creates resources | Yes |
Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.
Prompts that work
- List the AWS Config rules in us-east-1 and show which ones have non-compliant resources
- Add the s3-bucket-server-side-encryption-enabled managed rule
- What is the compliance status of the encrypted-volumes rule?
Before anything runs
Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.
Frequently asked questions
- Can OrchestrAI fix non-compliant resources found by AWS Config?
- Not through Config itself. It reports compliance status, but there is no remediation operation, so you would fix the resource directly, for example by enabling S3 encryption through the S3 operations.
- Does OrchestrAI enable the AWS Config recorder?
- Yes, there is an operation to create the configuration recorder. Rule creation is medium risk with confirmation, and reading compliance is low risk.
- Which AWS Config operations need an extra approval step?
- One operation carries a step-level approval gate on top of plan confirmation: Create AWS Config Rule. None of them is classed destructive.
Other AWS services
Related integrations
Try it on your own account
Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.
Unused credits refunded in your first 14 days.