Client Onboarding · Transparent · Least-Privilege

Exactly what happens
when we start working together

No black boxes. Here's every step of onboarding — what goes into your AWS account, exactly how access is scoped (the AI bot is read-only), and the timeline from our first call to live. Most clients are fully live in 2–3 days.

✓ Read-only AI bot · Fully auditable · Revoke anytime · Zero downtime
🔒 Least-privilege by design
🔎 Auditable in your CloudTrail
⚡ Live in 2–3 days
🎛️ Cancel anytime
What goes into your account

Three things — pick any one, or all three

Each is independent. Take the AI DevOps bot on its own (read-only, no monthly), or add 24/7 monitoring and the live diagram. Everything is additive — nothing restarts, nothing touches your application data.

🛰️

24/7 Monitoring & Alerts

Your AWS account watched around the clock, with instant alerts in your Slack the moment something matters.

  • Cost-spike alerts before the bill surprises you
  • CPU / memory / disk thresholds (info → warning → critical)
  • Security & failed-login alerts
  • Daily backup-completion checks
  • Instance health & status alarms
  • Optional add-on — built via a scoped setup role I revoke once it's live
🤖

AI DevOps Bot in Slack

Your own AWS/DevOps expert living in a private Slack channel — ask it anything, any time, and it answers in seconds.

  • Answers questions about your AWS setup
  • Reviews configs & explains security posture
  • Read-only — it can look, never touch
  • Needs only read-only access — no write, no monthly
  • Stands alone — no new tool to learn, it's just Slack
🗺️

Live Architecture Portal

A private, always-current map of your AWS network and traffic — now with a Drift tab that shows exactly what changed since the last scan. Behind your own login.

  • Interactive: pan, zoom, click any resource
  • VPCs, subnets, instances, databases, CDN & more
  • Drift detection — flags new public buckets, security groups opened to the internet, resized or removed resources between scans
  • Surfaces idle / forgotten resources you're paying for
  • Re-scans on demand or on a schedule — drift is tracked automatically
  • Private URL secured with your own password

The same portal also gives you a Security scorecard, Cost & FinOps insights, and a Well-Architected review — all behind your one login.

How it works — and why it's safe

Two access tiers — and you grant only what you need

The AI bot is read-only, always. Write access is needed only to build monitoring — a separate, scoped role you grant and I hand back. Here's exactly how it's scoped.

🔒

The AI bot is read-only — period

The bot assumes a scoped, read-only role you own (with a unique external ID). It can read your account to answer questions and map it — it cannot modify or delete a single resource. Want only the bot? Read-only is all you grant.

🛠️

Write access only to build monitoring — then revoked

If you add monitoring, you grant a separate setup role, scoped to just the services it creates (CloudWatch, SNS, Lambda). I use it once to provision, then revoke it the moment it's live. The bot never touches it.

🧩

Take only what you want

The bot stands alone with read-only access and no monthly. Monitoring and the live diagram are independent add-ons — pick any combination; nothing is bundled or forced.

🔎

Fully auditable & logged

Every API call — read or the one-time setup writes — is recorded in your own CloudTrail. Review exactly what was done, any time, and I'll walk your security team through it before we begin.

🚫

Zero downtime, zero data access

Setup is purely additive. Nothing restarts, nothing is installed on your production data path, and your application data is never touched.

🎛️

Revoke instantly, anytime

Delete any role or the Slack app whenever you want and access ends immediately — you own every one. Monthly services cancel with a single message.

The timeline

From first call to live — in days, not weeks

A clear, predictable path. You'll always know exactly what's happening and what's next.

1
Day 0 · 30-minute kickoff

We scope what you need

A short call to understand your stack and goals. You decide what you want — just the AI bot, or add monitoring and the diagram. Nothing is bundled; you pick.

2
Day 0–1 · Grant access

You grant access — scoped, and on your terms

From a template I send, you deploy a scoped read-only role (external ID, two clicks) for the bot. Adding monitoring? You also grant a separate setup role I use only to build it — and revoke once it's live. No keys to email around.

You own every role and can delete it anytime.
3
Day 1 · Deploy

I stand up whatever you chose

From my battle-tested toolkit, I deploy your Slack bot and — if you chose them — monitoring & alerts and the architecture diagram. Idempotent and repeatable; once monitoring is live, the setup role is handed back.

4
Day 2 · Go live

Alerts flow, bot is live, diagram is ready

CloudWatch alerts start landing in your Slack, your AI DevOps bot is online, and you get a private URL + login for your live architecture diagram.

5
Day 2–3 · Walkthrough

We review it together

A call to walk through your architecture diagram and the first findings — cost waste, security gaps, idle resources — with exact fixes. Then it's all yours.

Ongoing

Monitored, optimized, no lock-in

I keep watch, send a monthly optimization review, and you can cancel any month with one message. No contracts, no exit fees.

Don't take my word for it

Try my open-source security audit yourself

My read-only AWS security audit is public and MIT-licensed — install it and run it on your own account right now to see exactly the kind of rigor I bring. The client deployment automation itself stays private, but everything it does in your account is strictly read-only and fully logged in your own CloudTrail, so your team can audit every action.

github.com/davidgomezbravo/aws-audit — my open read-only AWS audit toolkit

pip install aws-audit-checklist — try it on your own account right now

Open source on GitHub pip install aws-audit-checklist
your-account — read-only audit
$ pip install aws-audit-checklist
$ aws-audit --report
# scanning IAM, S3, EC2, RDS, VPC … read-only
30-point security checklist
cost-waste & idle resources
backup & recovery checks
# → interactive report + exact fix commands
nothing changed in your account
AI DevOps Bot & 24/7 Monitoring — Technical & Security Architecture document cover
10-page PDF
For your engineers & security team

The full technical & security architecture

  • Every AWS resource we deploy — and exactly what each one is for
  • How the AI agent connects read-only to your account, verified end-to-end
  • The Slack integration: Socket Mode, least-privilege scopes, no open endpoint
  • The nine-layer defense-in-depth model & the gaps it closes
  • Data handling, the instant kill switch, and what we need from you

🔒 No spam — just the document, and the occasional note when it matters. Unsubscribe anytime.

What I'll need from you

Almost nothing — and that's the point

Three small things to get started. I handle the rest.

1

An AWS account — yours, or a dedicated sub-account. You'll deploy the read-only role from a template I send (plus a scoped setup role only if you add monitoring).

2

A few teammates to invite — I host the bot in a private Slack channel and add whoever should use it. Nothing for you to set up on Slack.

3

30 minutes — for the kickoff call. After that, you can be hands-off.

Ready to see your AWS account clearly?

Book a free 30-minute kickoff. I'll walk you through the plan and answer anything — no pressure, no charge before work is done.

Book your kickoff call →

Or see services & pricing →

contactme@itsdavidg.co · Read-only. Fully auditable. Cancel anytime.