Changelog
All notable changes to Prism and its documentation are listed here, with the most recent entries first.
August 2026
Amazon Detective (Security Hub)
Released: August 2026
Amazon Detective joins the Security Hub as its sixth capability, bringing behavior-graph investigation alongside compliance posture, threat detection, data security, vulnerability management, and AWS Config recording.
Highlights
- Behavior-graph investigation across your organization: one administrator account owns a behavior graph built from AWS CloudTrail management events, Amazon VPC flow logs, and Amazon GuardDuty findings, and every other account joins it by invitation. Detective builds one behavior graph per region, so each region you cover is separate coverage.
- Investigations, not posture findings: each finding is an investigation report naming the IAM user or role examined, the severity Detective assigned, the analysis status, and the time window analysed. They appear in the unified Security Hub findings inbox alongside the other engines'.
- Detective does not create investigations on its own: it recommends entities worth investigating, and a report exists only once someone runs an investigation. Prism reads those reports and never starts or re-triages one, so an empty list is Detective's expected steady state until an investigation is run from the AWS console. The dashboard and the findings list both say so rather than showing a bare "no results".
- Unrated investigations are shown as unrated: Amazon Detective returns severity with the full investigation report rather than in the list, so a freshly refreshed investigation has none until it is opened. A separate Unrated tile carries those rows instead of folding them into Informational or dropping them, so the severity strip always adds up.
- Root-email verification surfaced where it fails: AWS verifies each member's real root user address asynchronously, so a wrong address fails several minutes after the enrollment appears to succeed. A verification-failed account gets an inline root email field pre-filled with the rejected address, because retrying with the same address fails identically.
- Two status columns, deliberately: every row shows Prism's phase and Amazon Detective's own member status side by side, always. They frequently disagree while both are true,
ACCEPTED_BUT_DISABLEDbeing the important case: the account joined the graph and is not ingesting, and the action is Start monitoring, not Retry. - Standing, enumerated permissions: a named
CKPrism-Detective-Permissionspolicy grants exactly eleven Detective actions on each enrolled account's access role, with no service wildcards, no AWS Organizations actions, no service-linked role, and no permission to start or re-triage an investigation. - Unavailable rather than broken on unpaired self-hosted installs: a self-hosted deployment not paired with CloudKeeper SaaS cannot resolve member root emails, so Detective's capability card shows the reason in place of an Enable button instead of offering an enable that would fail.
See Detective for the full guide.
Amazon Inspector (Security Hub)
Released: August 2026
Amazon Inspector joins the Security Hub as its fifth capability, bringing software vulnerability management alongside compliance posture, threat detection, data security, and AWS Config recording.
Highlights
- Vulnerability scanning across your estate: continuously scan EC2 instances, ECR container images, Lambda functions, and code repositories for known CVEs, insecure code, and unintended network exposure.
- No delegated administrator: Inspector uses a flat peer model. Each account is enabled independently through its own access role, no administrator account is nominated, no invitations are sent, no AWS root email addresses are needed, and no management-account access is ever required. Prism, not AWS, aggregates the results.
- Five selectable scan types: choose EC2, ECR, Lambda dependencies, Lambda code, and code repositories independently. Inspector bills per resource scanned, so this selection is the main cost lever, and it can be changed at any time from Settings.
- Top CVEs across the organization: rank the vulnerabilities generating the most findings estate-wide, with the highest Inspector score recorded for each and whether a fix is published.
- Severity breakdown including UNTRIAGED: six severity tiles.
UNTRIAGEDmeans AWS has not yet assigned a severity, which is not the same as informational. - Fix availability: see how many findings already have a vendor fix, to separate what you can remediate today from what is waiting on a vendor.
- Per-account retry and Fix roles: accounts enrol independently, so partial success is a normal outcome. Failed accounts are listed individually with a Retry action, and a Permissions tab scans every account's access role and re-applies the required policy.
- Active-only findings cache: each refresh caches the findings AWS currently reports as active and prunes those it no longer reports, so remediated vulnerabilities drop out instead of accumulating.
See Inspector for the full guide.
July 2026
Security Hub (Organization Services)
Released: July 2026
Prism now offers Security Hub as a second Organization Services capability alongside CloudTrail. It centralizes cloud security posture, threat detection, and data security across every AWS account in your organization, under one umbrella with four capabilities.
Highlights
- Security Hub CSPM: enroll all member accounts under a delegated administrator, evaluate them against up to six AWS compliance standards, and drill down from standard to control to individual resource check with control-based compliance scores.
- Amazon GuardDuty: enable threat detection across accounts and regions, with a threat dashboard, per-type and per-account breakdowns, and an archive/unarchive workflow.
- Amazon Macie: enable S3 data-security posture across accounts and regions, with an S3 bucket posture inventory (public access, encryption, external sharing), policy and sensitive-data findings, and optional automated sensitive-data discovery (off by default, billed per GB of data inspected).
- AWS Config foundation: Prism provisions and manages the AWS Config recorders that Security Hub standards depend on, with minimal or record-all scope and a one-click inline enable prompt.
- Add engines anytime: enable a second engine after your first from the Configuration page.
- Organization Services users: grant Organization Services access to non-admin realm users without giving them the Admin Portal.
Security Hub is available as a beta feature. See Security Hub for the full guide.
June 2026
Google Workspace Sync
Released: June 2026
Prism can now provision users and groups from Google Workspace automatically. Because Google Workspace cannot push outbound SCIM to a custom endpoint, Prism pulls the directory from Google's Admin SDK on a schedule and reconciles it into your realm. It is the Google equivalent of SCIM provisioning.
Highlights
- New Google Workspace Sync card in Preferences > SCIM: connect a Google service account, set the impersonated admin and sync interval, then enable scheduled sync.
- Provisions user create and update, suspend and reactivate, group create and delete, and group membership. A manual Sync now runs an immediate reconciliation.
- Deletions are safe: a user removed from Google is disabled, not deleted (reversible), and an existing Prism user that matches by email is adopted rather than duplicated.
- Email addresses are immutable and group names are not renamed on sync, which protects downstream references such as permission-set assignments.
- Users and groups from other identity providers (Okta, Microsoft Entra ID) or created manually are never modified or deleted.
See Google Workspace Sync for the full guide.
Read-Only Admin Access
Released: June 2026
Admins can now be granted read-only access to the Prism Admin Portal. A read-only admin can sign in and view everything, including the configured permission sets and the SCP/Organizations policies currently applied, along with users, groups, assignments, accounts, and identity providers, but cannot create, edit, or delete any resource.
Highlights
- New Read-only access level, selectable when promoting a user in Preferences > Admin Management.
- Switch an existing admin between Full admin and Read-only at any time with the per-row Make Read-only / Make Full Admin action (Super Admin only).
- All modification controls are disabled for read-only admins, and any change is blocked server-side, view-only is enforced, not just hidden in the UI.
- Scoped to the Admin Portal only: a read-only admin's JIT access and AWS SSO sign-in are unaffected.
See Preferences > Admin Management for the full guide.
May 2026
Passwordless Passkeys
Released: May 2026
Workforce users can now sign in with a passkey, a FIDO2 credential (platform biometrics, a phone, a hardware security key, or a password manager), instead of a password. Admins enable it per realm and enforce it per user alongside the existing authenticator-app (TOTP) option.
Highlights
- New Passwordless Passkeys toggle in Preferences > Admin Management enables passkey sign-in for the realm.
- Enforce Authenticator app or Passkey per user from the Multi-Factor Authentication panel.
- Enrolled at next login; afterward users sign in passwordless via the "Sign in with passkey" button. Password + authenticator-app stays available as a fallback.
See Preferences > Admin Management for the full guide.
Permission set Relay state
Released: May 2026
Permission sets now accept an optional Relay state, an AWS console URL the user is forwarded to immediately after federation. Use it to land each permission set on the page that matches its purpose (an EC2 operator goes to the EC2 console, a billing reviewer goes to the billing console, and so on).
Highlights
- New Relay state field on the permission set create and edit forms (up to 320 characters; AWS-allowed character set).
- Configured value is shown on the permission set detail view.
- Takes effect on the next sign-in, existing assignments do not need to be re-issued.
- Empty relay state preserves today's behavior: users land on the default AWS console homepage.
See Permission Sets > Relay state for the field reference and ready-to-paste examples.
February 2026
Prism Documentation Site - Initial Release
Released: February 2026
The Prism documentation site has been published with comprehensive coverage of all three Prism portals and platform capabilities.
What's Included
Getting Started
- Prerequisites and system requirements
- Initial setup guide for new organizations
- First login instructions for all portals
- Quick start guides for admins, JIT users, and CloudTrail users
Admin Portal Documentation
- Dashboard overview
- User management: create, edit, delete users, manage MFA, assign to groups
- Group management: create, delete, manage members
- Permission set management: create, edit, delete, AWS managed policies, inline IAM policies
- Assignment management: create, delete, user assignments, group assignments
- AWS account management: onboard, rename, manage owners, delete
- Identity provider configuration: Google OAuth, Microsoft OAuth, custom OIDC
- Custom application configuration: SAML applications
- Preferences: admin management, SCIM configuration, API tokens, replication, log export settings
- Logs: audit logs, access logs
JIT Access Portal Documentation
- Authentication and portal access
- Request access: standard and custom permission sets
- My requests and active sessions tracking
- Approver guide: pending approvals, request history, approve/reject workflow, manage sessions, owned accounts
CloudTrail Documentation
- Trail list overview
- Trail creation wizard: trail settings, account selection, S3 bucket configuration, event configuration
- Trail detail view and trail editing
- Event types: management events, data events, insight events, network activity events
Troubleshooting
- Login and authentication issues
- SSO configuration problems
- Permission and access errors
- JIT request issues
- CloudTrail setup issues