No black boxes. Here's every step of onboarding — what goes into your AWS account, exactly how access is scoped (the AI bot is read-only), and the timeline from our first call to live. Most clients are fully live in 2–3 days.
Each is independent. Take the AI DevOps bot on its own (read-only, no monthly), or add 24/7 monitoring and the live diagram. Everything is additive — nothing restarts, nothing touches your application data.
Your AWS account watched around the clock, with instant alerts in your Slack the moment something matters.
Your own AWS/DevOps expert living in a private Slack channel — ask it anything, any time, and it answers in seconds.
A private, always-current map of your AWS network and traffic — now with a Drift tab that shows exactly what changed since the last scan. Behind your own login.
The same portal also gives you a Security scorecard, Cost & FinOps insights, and a Well-Architected review — all behind your one login.
The AI bot is read-only, always. Write access is needed only to build monitoring — a separate, scoped role you grant and I hand back. Here's exactly how it's scoped.
The bot assumes a scoped, read-only role you own (with a unique external ID). It can read your account to answer questions and map it — it cannot modify or delete a single resource. Want only the bot? Read-only is all you grant.
If you add monitoring, you grant a separate setup role, scoped to just the services it creates (CloudWatch, SNS, Lambda). I use it once to provision, then revoke it the moment it's live. The bot never touches it.
The bot stands alone with read-only access and no monthly. Monitoring and the live diagram are independent add-ons — pick any combination; nothing is bundled or forced.
Every API call — read or the one-time setup writes — is recorded in your own CloudTrail. Review exactly what was done, any time, and I'll walk your security team through it before we begin.
Setup is purely additive. Nothing restarts, nothing is installed on your production data path, and your application data is never touched.
Delete any role or the Slack app whenever you want and access ends immediately — you own every one. Monthly services cancel with a single message.
A clear, predictable path. You'll always know exactly what's happening and what's next.
A short call to understand your stack and goals. You decide what you want — just the AI bot, or add monitoring and the diagram. Nothing is bundled; you pick.
From a template I send, you deploy a scoped read-only role (external ID, two clicks) for the bot. Adding monitoring? You also grant a separate setup role I use only to build it — and revoke once it's live. No keys to email around.
From my battle-tested toolkit, I deploy your Slack bot and — if you chose them — monitoring & alerts and the architecture diagram. Idempotent and repeatable; once monitoring is live, the setup role is handed back.
CloudWatch alerts start landing in your Slack, your AI DevOps bot is online, and you get a private URL + login for your live architecture diagram.
A call to walk through your architecture diagram and the first findings — cost waste, security gaps, idle resources — with exact fixes. Then it's all yours.
I keep watch, send a monthly optimization review, and you can cancel any month with one message. No contracts, no exit fees.
My read-only AWS security audit is public and MIT-licensed — install it and run it on your own account right now to see exactly the kind of rigor I bring. The client deployment automation itself stays private, but everything it does in your account is strictly read-only and fully logged in your own CloudTrail, so your team can audit every action.
→ github.com/davidgomezbravo/aws-audit — my open read-only AWS audit toolkit
→ pip install aws-audit-checklist — try it on your own account right now
Your download is starting, and I’ve emailed the PDF to you too. If it doesn’t begin automatically, click here to download it. Questions? Just reply to that email or reach me at contactme@itsdavidg.co.
🔒 No spam — just the document, and the occasional note when it matters. Unsubscribe anytime.
Three small things to get started. I handle the rest.
An AWS account — yours, or a dedicated sub-account. You'll deploy the read-only role from a template I send (plus a scoped setup role only if you add monitoring).
A few teammates to invite — I host the bot in a private Slack channel and add whoever should use it. Nothing for you to set up on Slack.
30 minutes — for the kickoff call. After that, you can be hands-off.
Book a free 30-minute kickoff. I'll walk you through the plan and answer anything — no pressure, no charge before work is done.
Book your kickoff call →contactme@itsdavidg.co · Read-only. Fully auditable. Cancel anytime.