Getting Started
Enforcer-CCA is designed to be plug-and-play with your existing cloud infrastructure. It integrates seamlessly without requiring agents on your workloads.
Prerequisites
Before integrating Enforcer-CCA, ensure you have:
- An active AWS account and/or a Kubernetes cluster (Azure and GCP are on the roadmap).
- IAM permissions to create the read-only integration role Enforcer uses for evaluation.
Connecting your environment
Everything is done from the Enforcer dashboard — there is nothing to install in your cloud account and no agent to deploy on your workloads:
- Create an environment. An environment groups the accounts and clusters you want scored together (for example,
Production AWS). - Add an adapter. Under Adapters, connect a read-only AWS credential or a Kubernetes service account. The adapter defines which resource types Enforcer evaluates — S3, IAM, EC2, security groups, RBAC, network policies, and more.
- Run your first scan. Trigger a scan from the dashboard (or schedule recurring scans under Workflows). The drift flow discovers your resources, evaluates them against the ISO 27001-mapped policy set, and records resource-level evidence for every check.
Once connected, the platform immediately begins evaluating your environment against the default policy baseline — every finding traceable to the exact resource, policy, and timestamp.