--- title: "Onboard an AWS account with Zesty platform UI" slug: "integrate-and-onboard-an-aws-account-with-zesty-1" updated: 2026-07-19T15:15:53Z published: 2026-07-19T15:15:53Z canonical: "docs.zesty.co/integrate-and-onboard-an-aws-account-with-zesty-1" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.zesty.co/llms.txt > Use this file to discover all available pages before exploring further. # Onboard an AWS account with Zesty platform UI This topic describes how to use the Zesty platform UI to onboard your AWS account with Zesty. Onboarding connects your account so you can benefit from the Zesty platform features. This topic is relevant for AWS Linked or Management accounts to use Zesty Commitment Manager, Kompass, and Zesty Disk. You onboard an account using the Zesty platform **Onboard account** page: ![](https://cdn.document360.io/0eb80240-664b-49f5-9181-5713ddf9f725/Images/Documentation/integrate_account_page_short(1).png) > [!NOTE] > Onboard with Terraform for Kompass > > You can also use Terraform to onboard a Linked AWS account for use with Kompass. For more information, see [Onboard an AWS Linked account for Kompass with Terraform](/v1/docs/integrate-an-aws-account-for-kompass-with-terraform). Onboard an account when you need to: - Add a new organization to the Zesty platform. - Add an account to an existing organization on the Zesty platform. During onboarding, you will be transferred to your AWS Management Console. There, you’ll use a CloudFormation stack to create an IAM role which then onboards your AWS account with Zesty. #### Prerequisites - Access to the Zesty platform. For more information, contact [Customer Support](https://zesty.co/contact-us/?support). - The AWS account to be onboarded has permissions to create IAM roles and CloudFormation stacks. The required permissions are shown on the **Onboard account** page. ![](https://cdn.document360.io/0eb80240-664b-49f5-9181-5713ddf9f725/Images/Documentation/integration_permissions.png) - You are connected to the AWS account to be onboarded. - See the following table to determine which Zesty products require access to the CUR data: | Product | AWS account type | CUR | | --- | --- | --- | | **Commitment Manager** | Management | Required | | **Zesty Disk** | Linked | No CUR - Cost and savings are estimated based on AWS list price | | Management | Optional - With a CUR, Zesty can show precise cost and savings | | **Kompass** | Linked | No CUR - Cost and savings are estimated based on AWS list price | | Management | Optional - With a CUR connected to Athena, Zesty can show precise cost and savings | - If CUR access is being provided, the onboarding process will prompt you to enter the necessary values. These are the requirement for CUR data: - Zesty supports Legacy CUR and CUR v2.0, with a minimum of 24 hours of data. To create a Zesty-compatible CUR, see [Create an AWS CUR](/v1/docs/create-an-aws-cur). - Permissions to access the CUR and information about where it is stored (e.g., S3 bucket path). - When the **CUR data is for Kompass**, you need the following additional AWS prerequisites: - **crawler-cfn.yml** file is in the CUR S3 bucket. **Note**: this file may not be present until up to 24 hours after first creating a CUR. - AWS account ID. - Information about Athena resources (S3, Athena, Glue Data catalog). You can find these details in the AWS Console **Athena** section. #### To onboard an account with Zesty using the Zesty platform: 1. Open the **Onboard account** page: If you are already on the page, skip to #2. 1. From the **Admin** section of the Zesty platform main menu, select **Organization Settings > Accounts**. The **Accounts** page displays existing accounts. 2. Click **Add account**. The Onboard account page is displayed: ![](https://cdn.document360.io/0eb80240-664b-49f5-9181-5713ddf9f725/Images/Documentation/integrate_account_page(1).png) 1. In **Step 1**, choose whether the AWS account is a **Linked account** or a **Management account**. 2. In **Step 2**, choose the products to activate. 3. In **Step 3**, configure the CloudFormation stack: **Note**: You may not see all the fields described here. They will vary depending on the account type and product you chose in the previous steps and the CUR format that you choose here. 1. Select the region where to create the stack that will be used for onboarding. 2. Enter the details of the CUR (for Management accounts): (You can find these details in the AWS Console **Billing and Cost Management** section.) 1. Select the format of your CUR: **Legacy CUR**, **CUR 2.0**, or **None** 2. Enter the CUR export name (for v2.0 only). 3. Enter the CUR S3 bucket. **Example**: s3://zesty-cur/prod-v2 3. Enter the Athena details (required for Kompass). You can find some of the following details in the AWS Console **Athena** tab. - **Region**: Region where the source is located - **Bucket name:** the bucket where Athena query results are stored - **Database**: the name of the Athena database - **Table**: the Athena table name (in the Athena tab under your AWS database) - **Account ID**: ID of the AWS account - **Workgroup**: The Athena workgroup (in the Athena tab) - **Catalog**: The Athena data source (in the Athena tab) 4. In **Step 4**, create the IAM role: **Note**: Before proceeding, ensure that you are logged into the account that you are onboarding. 1. Review and approve the security content of the IAM role. 2. Click **Create IAM role**. Zesty redirects you to the AWS Console to create a CloudFormation stack. 3. In the AWS Console, scroll down to the **Capabilities** section and select **I acknowledge that AWS CloudFormation might create IAM resources.** 4. Click **Create stack**. In the AWS console, the **CloudFormation > Stacks** page is displayed. The Events tab shows the different events taking place. When the process is done, the CREATE_COMPLETE status is displayed. 5. In the AWS Console **Outputs** tab, copy the full **ZestyRoleArn** value and paste it in the **Role ARN** field at the bottom of the Zesty **Onboard account** page. For example: ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXc56rm_Nr02EKo5rXbz583TvyR1RQdqVWFEbjV0vhMz7lCmQHEyeEdK_dazRt41LtmUg8k8nICuLpEwMblTlhup9cERMRh0G773bKhgL91N-BvDAJqxG_E2mnYbc2AXTnr-Ct3MQQ?key=AYbVHJThLSE3vnvY8t_vIP3G) 5. Click **Connect account**. Zesty takes a few moments to finalize the onboarding. If you receive an error message or require other assistance, contact [**Customer Support**](https://zesty.co/contact-us/?support). 1. From the AWS Management Console, add permissions (required for Kompass): This process is explained in the [AWS Edit IAM policies](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_manage-edit-console.html) help topic. You can see the permissions [here](/v1/docs/aws-iam-permission-requirements#kompass-permissions). 1. Open IAM roles. 2. Click the recently created IAM. 3. In the **Permissions policies** section, click the policy name. 4. Add the following permissions so Zesty can access the result bucket: ```json           {            "Sid": "ZestyCURBucketAccess",            "Action": [                "s3:Get*",                "s3:List*"            ],            "Effect": "Allow",            "Resource": "arn:aws:s3:::[CUR RESULTS BUCKET NAME]"        },        {            "Sid": "ZestyCURBucketAccess",            "Action": [                "s3:Get*",                "s3:List*"            ],            "Effect": "Allow",            "Resource": "arn:aws:s3:::[CUR RESULTS BUCKET NAME]/*"        },        {            "Sid": "ZestyAthenaResultsWrite",            "Effect": "Allow",            "Action": [                "s3:PutObject"            ],            "Resource": "arn:aws:s3:::[ATHENA RESULTS BUCKET NAME]/*"        }, ``` 5. Click **Next**. 6. On the **Review and save** page, review **Permissions defined in this policy** and then click **Save changes**.