Skip to main content

SaaS Quickstart

Get started with Infracast SaaS in under 5 minutes. No infrastructure to manage — just sign up and connect your first data source.

Prerequisites​

  • A cloud account (AWS, Azure, or GCP) with read-only IAM credentials
  • OR network device credentials (Cisco, Palo Alto, etc.)
  • OR Active Directory with LDAP read access

Step 1: Create Your Account​

  1. Go to app.infracast.io
  2. Click Sign Up and create your account
  3. Verify your email address

Sign-up automatically creates:

  • An Account (your billing entity)
  • A Tenant (your customer organization, named after your company)
  • A default Workspace inside that tenant (your data environment)
  • Your user, set as Account Owner and Tenant Admin

You'll land directly in the default workspace and can start running discoveries immediately.

Step 2: (Optional) Add More Workspaces​

Most customers stay with the auto-created default workspace. If you need hard data isolation between environments — for example, separate Prod, Staging, and Lab — you can create additional workspaces from Settings → Workspaces → New Workspace.

Workspace Name: staging
When to add workspaces

Add workspaces when you need hard data isolation: prod vs staging, separate AWS accounts, MSP customer environments, or compliance scope separation. See Multi-Workspace Patterns for guidance.

Use the workspace switcher in the header to flip between workspaces without re-authenticating.

Step 3: Add Your First Credential​

Navigate to Settings → Credentials and add a credential for your first data source.

  1. Click Add Credential
  2. Select AWS as the provider
  3. Choose authentication method:
    • IAM Role (Recommended): Cross-account role with arn:aws:iam::YOUR_ACCOUNT:role/InfracastReadOnly
    • Access Keys: For quick testing (not recommended for production)
Minimum IAM Policy
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "InfracastDiscoveryReadOnly",
"Effect": "Allow",
"Action": [
"ec2:Describe*", "ec2:Get*", "ec2:List*",
"s3:GetBucket*", "s3:GetEncryptionConfiguration", "s3:GetLifecycleConfiguration", "s3:ListAllMyBuckets", "s3:ListBucket",
"iam:Get*", "iam:List*", "iam:GenerateCredentialReport", "iam:SimulateCustomPolicy", "iam:SimulatePrincipalPolicy",
"rds:Describe*", "rds:ListTagsForResource",
"eks:Describe*", "eks:List*",
"ecs:Describe*", "ecs:List*",
"ecr:Describe*",
"lambda:Get*", "lambda:List*",
"elasticloadbalancing:Describe*", "autoscaling:Describe*",
"route53:Get*", "route53:List*",
"cloudfront:Describe*", "cloudfront:Get*", "cloudfront:List*",
"kms:Describe*", "kms:Get*", "kms:List*",
"secretsmanager:Describe*", "secretsmanager:List*",
"cloudtrail:Describe*", "cloudtrail:Get*", "cloudtrail:List*",
"logs:Describe*",
"config:Describe*", "config:Get*", "config:List*",
"securityhub:Describe*", "securityhub:Get*", "securityhub:List*",
"guardduty:Get*", "guardduty:List*",
"inspector2:BatchGetAccountStatus",
"access-analyzer:Get*", "access-analyzer:List*",
"organizations:Describe*", "organizations:List*",
"sns:Get*", "sns:List*", "sqs:Get*", "sqs:List*",
"dynamodb:Describe*", "dynamodb:List*",
"elasticache:Describe*", "elasticfilesystem:Describe*", "redshift:Describe*",
"es:Describe*", "es:List*", "kafka:List*",
"acm:Describe*", "acm:List*",
"cognito-idp:Describe*", "cognito-idp:List*",
"directconnect:Describe*", "wafv2:List*",
"cloudformation:Describe*", "cloudformation:Get*", "cloudformation:List*",
"network-firewall:Describe*", "network-firewall:List*",
"tag:GetResources", "tag:GetTagKeys"
],
"Resource": "*"
}
]
}

Step 4: Run Your First Discovery​

  1. Navigate to Jobs → Discovery
  2. Click New Discovery Job
  3. Select your credential and target regions
  4. Click Start Discovery

Discovery typically takes 2-5 minutes for a small AWS account (< 1,000 resources).

Step 5: Explore the Topology​

Once discovery completes:

  1. Go to Topology
  2. Use the search bar to find a resource (e.g., "prod-vpc")
  3. Click a node to see its properties and connections
  4. Use Trace Path to check network reachability

Step 6: Run Your First Compliance Audit​

  1. Go to Settings → Compliance Frameworks
  2. Enable the frameworks relevant to your organization (e.g., NIST 800-53, CIS AWS)
  3. Navigate to Findings to see compliance violations
  4. Click any finding to see remediation guidance

Next Steps​

Troubleshooting​

Discovery shows 0 nodes​

  • Verify your IAM credentials have the required permissions
  • Check that you selected the correct regions
  • Look at the job logs for specific errors

Missing resources​

  • Some resource types require additional IAM permissions
  • Cross-account resources need separate credentials
  • Check if resources are in regions you didn't select

Rate limiting errors​

  • AWS API rate limits can slow discovery
  • Infracast automatically backs off and retries
  • For large accounts (10K+ resources), expect 10-15 minute discovery times