agent's idle-resource sweep skipped the acquired company's account - the role assumption failed silently and it...
Fixes an idle-resource sweep that silently skipped an account when role assumption failed, then reported everything clean. Use when a sweep reported clean but an account was never actually checked, especially after an acquisition. It detects the silent skip, fixes the trust relationship, re-runs the sweep on the skipped account, and makes unreachable accounts report as unknown, never clean.
TL;DR: Treat any unreachable account as unknown, never clean - and fix the trust relationship in the acquired account so the sweep can actually reach it. Acquired accounts bring their own IAM setup, and the trust the agent relies on does not exist there yet. The bug is not the failed role assumption; it is the sweep catching the failure, continuing, and reporting all clean for an account it never saw.
agent's idle-resource sweep skipped the acquired company's account - the role assumption failed silently and it reported "all clean"- Prove the skip happened: compare the sweep's covered-account list against the real account inventory, and check the agent's logs for the failed role assumption. Expected: you find the assume-role error buried in debug logs and the account missing from the sweep.
- Fix the trust relationship: the acquired account's audit role must trust the agent's source account and principal. Update the trust policy, then retry the assumption by hand. Expected: the assume-role call succeeds and returns credentials.
- Re-run the sweep scoped to the previously skipped account. Expected: the idle-resource findings for that account - which may be substantial, since it has never been swept.
- Change the sweep's completion rule: any account that cannot be reached is reported as unknown, never clean, and the run alerts on it. Expected: the next silent failure becomes a loud one.
Use this when
- A sweep reported clean but an account was never actually checked
- Role assumption fails for a new or acquired account
- You need sweep results to distinguish checked and clean from not checked
Not for this skill when
- The account was checked and genuinely has no idle resources - verify the coverage list to be sure
- The role assumption fails for a deliberately excluded account - document the exclusion explicitly
- The sweep covers one account only by design - then the scope statement should say so
Variant phrasings
- idle sweep skipped account role assumption failed
- agent reported all clean but never checked acquired account
- how to make cost sweep fail loudly on unreachable accounts
- cross account assume role silent failure cost audit
Why it happens
Acquired accounts come with their own IAM setup, and the trust relationship the agent relies on does not exist there yet. Most SDK assume-role calls raise an exception that is easy to catch and log at debug level - and a sweep that catches the exception and continues will happily report all clean for an account it never saw. The bug is not the failed assumption; it is treating failure as success.
Edge cases
- The acquired account may be in a different organization with its own payer. Sort out the billing relationship before assuming the sweep should cover it.
- Trust policies often restrict by external ID. Make sure the agent is configured with the right external ID for the acquired account.
- After fixing trust, historical data for the skipped period is still missing. Backfill the first sweep or annotate the gap so trends are not misleading.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_DryuDVpxYaU9FnPGWKUoIA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.