Skip to content

Cloud accounts overview

A cloud account is a connection between Patrol and a customer’s infrastructure — an AWS account, Azure subscription, GCP project, or private cloud. Once connected, Patrol can scan it for resources, build a topology view, and alert you to unexplained changes.

Cloud account scanning is independent of whether Patrol deployed the infrastructure — you can connect any account, even one managed entirely outside Patrol.

Cloud Accounts list showing connected accounts with their scan status and last-scanned timestamps

From Cloud Accounts → Add Cloud Account, fill in:

  • Name — a human-readable label (e.g. the AWS account alias or Azure subscription name)
  • Provider — AWS, Azure, Google Cloud, OpenStack, VMware, or Other/Custom
  • Customer — optionally link this account to a customer
  • Connection mode — how Patrol reaches the account (see below)

Add Cloud Account form

Patrol assumes a read-only role or service principal in the customer’s account and scans it directly. This is the recommended mode for public cloud providers (AWS, Azure, GCP).

See the provider-specific guides for setup steps:

For private or isolated clouds (OpenStack, VMware) where Patrol can’t reach the account directly, a lightweight collector process runs inside the customer’s network and pushes scan results to Patrol.

Collector support is currently being built out.

Once an account is connected:

  • Click Scan now on the account detail page to run an inventory scan immediately.
  • Toggle Auto-scan to run a scan every 6 hours automatically.

Each scan produces a snapshot — a point-in-time inventory of the account’s resources, grouped by category (compute, network, IAM, security, storage). Snapshots are visible in Scan history.

Cloud account detail page showing the Scan now button, auto-scan toggle, and scan history list

  • Drift Detection — compare snapshots against an accepted baseline and track unexplained changes
  • Topology — explore how resources are connected within a snapshot