Docs · Getting started
Try it on a sample company
A made-up company you can click through before connecting your own AWS: what it contains, what it never does, and how it goes away.
A new workspace has nothing in it, and step one of setting up is deploying a stack in your AWS. If you would rather see CloudGrant work first, load the sample company. It takes one click and touches nothing of yours.
What you get #
Pied Piper, the made-up startup from HBO's Silicon Valley:
- Five AWS accounts: a management account,
compression-apianddata-platform, each in production and development. - Four permission sets: AdministratorAccess, PowerUserAccess, ReadOnlyAccess and Billing.
- Seven people in six groups: engineering, devops, security, data, finance and contractors.
- Nine rules, including a two-person approval for production admin, a break-glass path for security, and one that lets you, the workspace owner, request dev admin yourself.
- Two weeks of history: auto-approvals, a two-person approval, a denial, an early hand-back, a break-glass, and one grant still live when you arrive.
- One request from Richard Hendricks, waiting for your approval. That is where the click lands.
What to do with it #
- Approve Richard on the Approvals page. The grant goes live with a countdown.
- Request dev admin for yourself on the Access page. A sample rule auto-approves it.
- Read the Audit log: who asked, who approved, what they got, when it ended.
- Change a rule and watch the request page react.
- Open Access review to see which standing access the review would flag.
What never happens #
- Nothing is created in AWS. There is no AWS behind the sample; every grant is recorded and answered without a call.
- No email goes to the sample people. Their addresses end in
.example, a domain reserved for documentation that cannot resolve. You still get the real notification when Richard's request is waiting. - Nothing leaves the workspace. The CSV export, the evidence pack and the audit feed to your SIEM are off while the sample is loaded, and say so.
- Invites wait. Your real team joins after the sample is gone, so nobody arrives to made-up data.
How it goes away #
Two ways, and both are complete:
- Remove sample data, on the banner every page shows while the sample is loaded.
- Connect your AWS. The moment a real connection is stored, the sample is removed first.
Removal takes the seven people, the nine sample rules, every request and grant, and every audit event from "sample company loaded" onward. A rule you added yourself stays. What the workspace recorded before the sample stays. The audit log then says the sample was loaded and removed, with who did each.
The sample cannot be loaded into a workspace that already has requests or grants of its own, because removal takes every request and grant.