AWS
AWS Dashboard
The first screen of an AWS project — inventory, cost charts, security checks and console logins.
Where an AWS project opens. It answers four questions in one screen: what do I have, what is it costing, is anything obviously insecure, and who has been signing in.
It re-scans every enabled region live each time you open it, so it takes a few seconds. The numbers are current, not cached.
Inventory
- EC2 instances across enabled regions, with a per-region breakdown.
- RDS database instances across enabled regions.
- S3 buckets in the account.
Regions that could not be read are listed with their error rather than being silently dropped — usually a missing permission. See Permissions.
Instances in regions you did not know you were using is the most common surprise here, and a frequent source of forgotten spend.
Cost charts
- Monthly — the last 12 months.
- Daily — the last 15 days, broken down by service.
Use the monthly chart to spot a steady climb, and the daily chart to find the day something changed. For the full breakdown go to Cost.
Security checks
Five checks against the whole account:
- CloudTrail enabled — without it there is no record of who did what in your AWS account. This is the one to fix first.
- CloudTrail production-ready — a trail exists, but is it multi-region, logging, and covering the right events?
- GuardDuty enabled — AWS's threat detection. See Security findings.
- Root account MFA — the root account is the one that can do everything. It should have multi-factor authentication. No exceptions.
- Account-level S3 Block Public Access — the setting that stops a bucket being made public by accident. Public S3 buckets are the classic data leak.
Also flagged: IAM console users without MFA, listed by name. See Users / IAM.
Each finding explains what it is and why it matters. They are read from your account every time, so fixing one in AWS makes it disappear here.
Console logins
Recent sign-ins to the AWS console, read from CloudTrail: who, when, and from where.
Worth a glance for logins at odd hours, from unexpected countries, or from accounts you thought were closed.
If everything is empty
- All regions error → the access key is wrong, or has no permissions. Replace it in Settings → Project.
- Cost charts are empty → Cost Explorer needs enabling once in the AWS
billing console, and the key needs
ce:GetCostAndUsage. - Security checks error → missing
cloudtrail:*,guardduty:*,iam:*ors3control:GetPublicAccessBlock.
Full list: AWS permissions.
