Wiv AWS Connectivity Architecture
Real-time data access and security framework for Wiv's AWS integration, detailing security architecture and data scopes for maximum optimization.
Written By Dotan Cohen
Last updated About 2 months ago
Wiv AWS Connectivity Architecture
Overview
Wiv is a high-performance FinOps platform built for real-time identification of cost-saving opportunities and anomalies. By securely integrating a Cross-Account IAM Role and AWS EventBridge, Wiv delivers a unique combination of deep visibility and instant responsiveness. This document details the security architecture and outlines the complete data scopes required to achieve maximum optimization.
The Security Handshake & Guarantees
All connectivity strictly follows AWS best practices for third-party SaaS integration, ensuring maximum security and trust.
Key Security Guarantees:
Metadata Focused: Operations concentrate on metadata scans to efficiently identify optimization opportunities.
Real-Time Intelligence: Wiv utilizes EventBridge for instant reaction to account changes, eliminating the delay of waiting for daily billing updates.
Encryption & Isolation: All sensitive connection metadata is stored exclusively within your account's Secrets Manager and is never retained on Wiv's side.
No Customer Data Access: Wiv is architected to prevent access to PII, database records, or application-level data.
Visual Architecture Flow

Wiv's Event-Driven FinOps: Real-Time Value and Permission Framework
The Strategic Value of Real-Time Triggers (AWS EventBridge)
Wiv's core architecture leverages Event-Driven Responsiveness, distinguishing it from traditional FinOps tools that rely on slow, periodic polling. This design enables Wiv to capture infrastructure changes instantly as they happen.
Why Real-Time is Essential: Delays, such as waiting 24 hours for a billing report, can result in thousands of dollars in wasted spending due to misconfigured, expensive resources. Real-time triggers allow Wiv to immediately identify, alert on, and prevent these costly anomalies.
Mechanism: Wiv uses AWS EventBridge Rules, configuring them to "listen" for specific lifecycle events that impact cost (e.g., changes in EC2 state, creation of a new RDS instance, or activation of Billing Alarms).
Secure Data Flow: When an EventBridge rule is triggered, it securely invokes an API Destination. This pushes the necessary metadata to Wiv's backend for immediate processing.
Permission Matrix: Detailed Overview
The comprehensive table below details all API actions granted to the WivAccessRole, categorized by functional domain. These permissions are primarily read-only, supporting deep analytical capabilities.
Deep-Dive: Necessary Automation and Write Permissions
To facilitate the real-time, event-driven workflows, Wiv requires a precise and surgical set of "Write" permissions. These actions are strictly limited to managing the necessary Wiv-related infrastructure within your account for secure, real-time data integration.
Conclusion
The Wiv connectivity framework is engineered for maximum safety and transparency. By combining a broad set of read-only analytics with focused, real-time event integration, Wiv delivers a proactive FinOps strategy that catches waste before it can accumulate. Every write permission is directly tied to the security and essential data delivery of your account's metadata.