How CloudFix works

How CloudFix works: A deep dive into roles and permissions

A deep dive into CloudFix roles and permissions. Learn how CloudFix uses AWS IAM to safely implement cost optimizations across your accounts with full control.

Update 2026: CloudFix now runs approved fixes through AWS Systems Manager in your account.

Every week, AWS releases more than 50 advisories in the form of blog posts to help their customers take advantage of the latest AWS recommendations, including cost and performance improvements. However, staying on top of every advisory and then creating and managing scripts for every recommendation is time consuming for cloud teams. That’s why we built CloudFix.

CloudFix helps companies reduce AWS costs and improve compliance with AWS best practices by providing ongoing cloud hygiene. CloudFix removes the burden on IT teams to track, test, and implement these advisories by adding the AWS-recommended optimizations to its always-growing “Fixer” library.

In this blog, we will go behind the scenes to understand how CloudFix helps you quickly and easily see your potential savings by safely connecting your AWS account.

Getting started with your AWS account

CloudFix allows you to connect multiple AWS accounts so that you can review all your recommendations from a single dashboard. CloudFix is completely transparent and purposefully uses roles to allow you to easily audit what the roles are doing.

An AWS CloudFormation template configures your account with two separate AWS IAM roles, so that CloudFix can both identify and execute fixes:

  1. “Finder”: a READ-ONLY role used to get resource and usage information, such as your cost and usage data, configuration data and CloudWatch metrics.
    CloudFix does not have permission to read actual user data. For example, we can read metrics about your AWS S3 bucket to see how much they cost but we cannot access any of the data in the bucket.
  2. “Fixer”: a separate role with a minimal, tightly scoped set of permissions, used only to carry out the fixes you approve.
    CloudFix does not require any elevated permission and will not make changes without your approval. Approved fixes run through AWS Systems Manager in your own AWS account.

IAM roles do not have any long-term credentials, passwords, or access keys. Instead, credentials are created dynamically and provided to the role only temporarily.

Scanning your AWS account for suggested recommendations

Once your AWS accounts are connected, CloudFix will scan each account using the Finder role. You can think of a Finder as a read-only process that scans and analyzes your AWS accounts for cost saving and performance improving opportunities.

Finders work from the usage metrics and metadata your AWS account already produces, such as your cost and usage data and configuration data, which are stored in your account. The Finder role accesses this data to make recommendations but does not read any content in your databases or any other stored data.

CloudFix will not suggest any blanket changes but instead uses the information and data to make specific recommendations, which change nothing until you approve them. CloudFix is also continuously scanning your accounts for any changes in your AWS environments or any new AWS advisories.

Implementing suggested fixers

CloudFix implements the AWS best practice of a “least privilege” model with no elevated permissions. Nothing runs until you approve it. Once you do, the fix runs as an AWS Systems Manager Automation runbook in your own AWS account, and every execution is logged, so you have a complete record of what changed and when.

You also have control over when to run fixers. As part of the approval process, you can choose to execute the fixer instantly, or to schedule it for a specific day and time. The CloudFix Finder-Fixer lifecycle is designed to be simple and straightforward while keeping you in control.

See how CloudFix runs approved fixes through AWS Systems Manager Automation, and browse the fixers CloudFix runs.


Ready to start saving on AWS? See how much you could cut from your cloud bill with a free cost optimization assessment, or explore CloudFix automated Finder/Fixers that eliminate waste across 30+ AWS services.

More from the blog

All 81 posts
  • CloudFix Automates AWS Cost Optimization

    CloudFix automates AWS cost optimization by finding and implementing savings across your accounts. See how StorageReview covers our re:Invent 2021 debut.

See which fixers apply to your account.

About 5 minutes to connect with read-only roles. Results typically within 24 hours.