Organization
The Organization feature is only turned on for projects created on an Organization plan (Organization 10/50/200, see Subscription). Nothing changes for a Standard plan that connects a single account - this document only covers onboarding and managing several accounts through AWS Organizations.
Terms used in this document:
- Organization project - a project created on an Organization plan. It holds one AWS Organization (a management account plus several member accounts).
- Connection - a single AWS account (in a single region) linked to Security Hero RMF. Same concept as AWS Connection in Project Settings.
- Management connection - the connection for that AWS Organization's management (billing) account. Exactly one per organization project.
- Member connection - a connection for any account in the organization other than the management account.
1. Connect the management account
The first step in organization onboarding is connecting the AWS Organization's management account. The connection process itself is the same as Project Settings > AWS Connection (enter the Account ID, create the CloudFormation stack, confirm the connection). What is different:
- You can create only one management connection per organization project.
- The CloudFormation template used for this connection is the same role as any other connection (based on the SecurityAudit and ReadOnlyAccess managed policies), with permission to read AWS Organizations added (
organizations:Describe*,organizations:List*). There is no separate template to create by hand for the management account. - The management account can be scanned too, and it counts toward your plan's account limit (Organization 10/50/200). If you have connected only the management account and no member accounts yet, you have already used one account of your limit.
- This connection is also what reads the organization's guardrail policies (SCPs/RCPs) - see 8. Organization policies.
Discovering member accounts only runs once the management connection's storage (customer-owned S3 + KMS) has finished onboarding. Attempting discovery before that is recorded as skipped and returns nothing. Right after connecting the management account, finish its KMS/S3 connection just as you would for any other connection.
2. Discover member accounts
Once the management connection is made and its storage is onboarded, run Discover now on the organization screen to read the accounts that belong to your AWS Organization. Discovery shows:
- The account list - account ID, name, email, status (Active / Suspended / Pending closure), organizational unit (OU) path, and account tags
- The OU (organizational unit) tree
- Whether each account already has a connection, and whether that connection's storage is onboarded
Discovery does not create connections. It only records what exists; creating connections is a separate, explicit step (bulk connection creation, below) so that running discovery can never spend your account capacity on its own.
An account that has left the organization is not removed from the list - it stays, marked "removed". Its connection, assessment history and reports are preserved: leaving the organization must not erase past evidence.
If discovery has never been run, the list is empty and shown as "not yet discovered", which is a different state from "there are no accounts".
3. Create connections for member accounts in bulk
You can pick discovered accounts and create their connections all at once. Give a list of accounts and regions (an account can have several regions, up to 3 per account), and the request is handled as follows:
- The whole batch is judged first. Account ID format, duplicates within the request, connections that already exist, the region limit per account, and your plan's account limit (which includes the management account) are all checked item by item.
- If any item is rejected - say, the last account would push you over your plan's limit - nothing is created by default. The screen shows the same per-item results a dry run would, so you can see what was rejected, adjust the list, and try again.
- A "dry run only" option lets you preview the per-item results without creating anything.
Connections created this way inherit the discovered account's owner and team values (the account tags described in 4) as the connection's defaults.
If a batch is only partly created because of the limit, you have to count which accounts made it through yourself. The account capacity that would have been spent is exactly what the check was about, so judging the whole batch first and creating nothing on a rejection is the safer default.
4. Owner and team
If an account discovered from AWS carries Owner/Team tags, those values are filled in automatically as the Owner and Team fields on the account and its connection. You can edit these later at any time from the connection's General tab.
Owner and team are not just informational - they also become the default assignee for new findings raised against that account, so keeping them up to date makes it easier to hand off remediation work later.
5. When an account has more than one connection: the primary connection (IAM analysis)
If you connect the same account in more than one region (up to 3 per account), asset scanning and configuration checks still run once per region, but IAM permission analysis runs only once per account - the roles, users and policies an account has are the same regardless of region, so there is no reason to repeat the analysis once per region.
- An account's first connection automatically becomes that account's primary connection (the one IAM analysis runs on).
- Running IAM analysis on a non-primary connection - manually, on a schedule, or as part of a group-wide run - is recorded as "skipped (duplicate account)" rather than actually running. This status stays visible in the execution history, so it reads as "another connection is already the primary one for this account" rather than a failure.
- You can move the primary flag to a different connection from Project Settings > General. Turning it off (without another connection taking it over) is only allowed when another connection for the same account already holds the flag - an account can never be left with no primary connection at all.
Combining several regions of the same account into a single connection is not available yet. For now, each account x region pair is its own connection, and only IAM analysis is consolidated per account through the primary flag described above.
6. Deployment package: StackSet or per-account quick-create links
Creating a connection and actually deploying the role, key and bucket into that account are two separate things. Instead of creating a CloudFormation stack by hand in every account, the organization screen offers a deployment package that handles many accounts at once.
The deployment package includes:
- A parameterized CloudFormation template (for a stack set) that works for every member account. Nothing account-specific is baked into the template;
ExternalId,SecurityHeroAccountId, and (when needed)CreateResourceExplorerIndexare supplied as parameters at deploy time. Every connection created through the organization path shares the same External ID, which is what lets one stack set cover every member account. - The parameter values to fill in for each account, and the list of target regions.
- Deployment instructions in Korean and English, plus an AWS CLI example you can run as-is from the management account (
create-stack-setfollowed bycreate-stack-instances). - A Quick Create link for each connection. Opening it takes you straight to a CloudFormation create-stack screen pre-filled for that account and region. In an environment where no public template location is configured yet, you get a template download instead of this link.
You deploy this yourself, from the management account (a service-managed stack set, targeted at the OUs or the whole organization you choose). Security Hero RMF does not create the stack set for you - that would require write access to your management account, and this connection is read-only by design, end to end.
If an account already has a Resource Explorer aggregator index in another region, deploy to that account with CreateResourceExplorerIndex=false (AWS allows only one aggregator index per account).
7. Verify all
Once the stack set has finished deploying, run Verify all from the organization screen. It checks every connection in the group at once (up to 5 at a time), and each result is the same as verifying that connection individually.
Beyond confirming the role can be assumed, verification also finds the KMS key and S3 bucket the stack set created by their standard names and completes the storage connection automatically. Because the stack set creates the key and bucket under names the platform already expects, there is no need to press "complete storage connection" separately for every account.
8. Organization policies (SCP/RCP)
Through the management connection, Security Hero RMF also collects the organization's guardrail policies - Service Control Policies (SCPs) and Resource Control Policies (RCPs) - and where each one is attached (organization root, an OU, or an account). This feeds IAM permission analysis and future capabilities that judge whether a permission is actually blocked by an organization policy.
- Policy bodies are never stored on our side. SCPs and RCPs are your own data, so the policy body is stored only in your own S3 bucket, connected to the management account. Our database keeps only the fact that the policy exists, where it is stored, and a hash of its content.
- Pick one account to see the policies that actually apply to it, in organization root -> OU chain -> account order. A level with nothing attached is still shown as such - leaving it out would make the chain look shorter than it really is. The
FullAWSAccesspolicy AWS attaches by default is shown too, when it is in effect. - A policy that disappears (deleted, or detached from a target) is not removed from the record either - it is marked "removed", so you can trace what restriction was in force at an earlier point in time.
If your organization has not turned on SCPs or RCPs at all, that policy type cannot have any policies to begin with. An empty list in that case does not mean "no policies" - it means "this organization does not use this policy type", and the screen shows which policy types are enabled alongside the list. Always check that indicator together with the list - an empty list on its own is easy to misread as "no guardrails at all".
9. The organization dashboard
Opening an organization project shows an organization-wide dashboard instead of the single-account dashboard. It includes:
- Organization score - a simple average of the risk score of every connection with a recent successful assessment (formula version
org-v0). This is a first-version summary, not a sophisticated formula weighted by account count or severity, so in an organization with a wide spread of account scores, look at the account ranking as well rather than the average alone. - Account ranking - each connection (account) listed with its score, findings by severity, open risk identities, and mean time to remediate (MTTR).
- Progress board - for every connection, when its last sync, assessment and IAM analysis finished and in what state (succeeded / failed / skipped / running / never run), plus the totals across the group.
- Top risk identities - the highest-severity, most-recent risk identities across the whole organization.
- Run all - one button to run sync, assessment and IAM analysis across every connection in the group at once. A group-wide run is tracked together as a single batch, and IAM analysis is automatically skipped on every connection that is not the primary one for its account, as described above.
10. The organization report
Unlike a single-account report (see Report), the organization report gathers the most recent successful assessment of every connection in the group into one document:
- An executive summary (organization score and account ranking)
- A section per account - score, severity breakdown and top findings for that account
- An appendix - the scope covered by the report (which connections), which accounts have never been assessed, and when each included assessment ran
An account that has never been assessed is not dropped from the report - it is called out as "not assessed". As with every other report, the export format is PDF.
11. How this relates to your plan
The Organization 10/50/200 plans allow connecting up to 10, 50 and 200 accounts respectively (see Subscription for pricing and comparison). The management account counts toward this limit, so connecting only the management account already uses one account of your allowance. Connecting more accounts than your plan allows requires upgrading to a larger band.