02Quickstart
From signup to your first scan in five minutes.
Seven concrete steps. The longest one (running the AWS connector) takes ninety seconds. Nothing here uses a long-lived secret, and every action is reversible from your own cloud console without telling us first.
What this checklist guarantees
- 01
Create your account
≈ 20 secSign in with Google or GitHub. No credit card. No verification email round-trip. A workspace is provisioned for you on first login.
Sign in - 02
Pick a cloud provider
≈ 10 secStart with the one that has the most spend — usually AWS. You can connect Azure and GCP afterwards. We never store long-lived secrets; every connector uses the provider's native trust model.
- 03
Run the CloudFormation one-click connector
≈ 90 secWe give you a CloudFormation template URL. Open it in your AWS console, accept the read-only IAM role, copy the Role ARN back. Total clicks: 4.
AWS setup guide - 04
Validate the connection
≈ 5 secAxiom calls STS GetCallerIdentity to prove it can assume the role. Green tick + region count appears in the dashboard. If it fails, the error tells you exactly which IAM permission to add.
- 05
Run your first scan
≈ 60 secClick 'Scan environment'. Cloud Agent inventories ~400 resources across all enabled regions in under a minute. You see findings appear in real time — cost waste, security drift, misconfigurations.
How scanning works - 06
Review the findings report
≈ variesFindings are ranked by severity + estimated impact. Each one has a one-click 'Generate fix' button that drafts a Terraform diff. Nothing executes yet — every change requires your explicit approval.
Approval workflow - 07
Approve your first fix (optional)
≈ 30 secPick a low-risk finding. Click 'Approve'. Axiom runs the Terraform plan with blast radius limits + verified rollback ready. The full audit trail (who, what, when, sha-256 rationale) is written to your immutable audit log.
Execution plans
After five minutes
- ✓ A connected, validated read-only AWS account.
- ✓ A full infrastructure inventory across every enabled region.
- ✓ A prioritized findings report with cost + security recommendations.
- ✓ An approval queue with draft Terraform fixes waiting on your sign-off.
- ✓ Zero stored credentials. Zero long-lived secrets. One revocable IAM role.
Read next
Need a human?
Most flows are documented — but we'll help if anything is unclear.