Clouds
A cloud account gives agents the infrastructure behind your system. Polylane syncs its resources into the topology, records every change, and checks each resource on a schedule.
What it does
Connecting an account discovers the resources your credentials can see and adds them to the topology as nodes, with edges for how they relate. Accounts re-sync on their own; the account header shows a Last synced time and a Sync with Cloud action for when you cannot wait. Once the first sync completes, anomaly checks run against every resource at the pace its tier sets, and advisories are computed from the topology as it fills in.
These providers connect as cloud accounts:
Cloud providers
Connect your infrastructure
Connect an account
Pick a provider
Open Settings > Clouds in the console and choose Connect a cloud account. AWS deploys a CloudFormation stack that creates a role in your account and the page waits until the stack reports back; most other providers take an API token or sign you in through OAuth. Each provider page at /integrations/<type> lists the exact credentials it needs, and from the terminal polylane cloud connect runs the same flow.
If nothing in your environment clicks console links, cloud accounts also connect entirely over the API: every provider page that supports it has a Pipeline tab with the exact calls, starting with /integrations/aws.
Let the first sync finish
The account header shows sync progress. Resources appear on the topology as they are discovered, and Polylane starts watching the account as soon as the first sync completes.
Review what Polylane watches
Open the account's Settings tab to confirm the check frequency and decide whether agents may write to the account. The tabs below show what the account page gives you from then on.
Read-only by default
Accounts start read-only: agents can call the provider's read endpoints, and any write call is refused with the reason. A workspace admin can turn Read-only off in the account's Settings tab, except for Kubernetes clusters connected through the agent, which stay read-only. Even with writes enabled, a direct provider write is held until you confirm it in the thread where you asked for it, and background runs nobody has written to stay read-only.
The account page
| Tab | What it shows |
|---|---|
| Cloud Graph | The account's slice of the topology, filterable by type. Select a node to open its resource page. |
| Problems | The fix runs on issues scoped to this account, one row per run with its severity and outcome, plus the account's recent check evaluations. |
| Alerts | Automatic triage for the account's alerts: alerts that fire become issues and get a fix run when confirmed. Shown for AWS, Cloudflare, Vercel, Render, Supabase and Convex. |
| Key questions | The questions Polylane works out are worth asking about the account, each paired with a query in the provider's own query language and rechecked on a schedule. Shown for AWS, Cloudflare, Vercel, Fly.io, Render, Supabase and Railway. |
| Repositories | The source code behind the account's resources, matched from your connected repositories or added by you. Discovery needs a connected GitHub. |
| Settings | Credentials, with Verify and Rotate; the Read-only switch; the anomaly check Frequency; Re-classify tiers; and provider-specific options such as AWS regions, Vercel telemetry, and monitoring for preview deployments. |
| Properties | The raw account record. |
Related
- Topology for how to read the graph the account fills in.
- Integrations for connect methods and what disconnecting removes.
- Issues for what the scheduled checks raise.