TL;DR: Treat any unreachable account as unknown, never clean - and fix the trust relationship in the acquired account so the sweep can actually reach it. Acquired accounts bring their own IAM setup, and the trust the agent relies on does not exist there yet. The bug is not the failed role assumption; it is the sweep catching the failure, continuing, and reporting all clean for an account it never saw.

```text
agent's idle-resource sweep skipped the acquired company's account  -  the role assumption failed silently and it reported "all clean"
```

1. Prove the skip happened: compare the sweep's covered-account list against the real account inventory, and check the agent's logs for the failed role assumption. Expected: you find the assume-role error buried in debug logs and the account missing from the sweep.
2. Fix the trust relationship: the acquired account's audit role must trust the agent's source account and principal. Update the trust policy, then retry the assumption by hand. Expected: the assume-role call succeeds and returns credentials.
3. Re-run the sweep scoped to the previously skipped account. Expected: the idle-resource findings for that account - which may be substantial, since it has never been swept.
4. Change the sweep's completion rule: any account that cannot be reached is reported as unknown, never clean, and the run alerts on it. Expected: the next silent failure becomes a loud one.

## Use this when
- A sweep reported clean but an account was never actually checked
- Role assumption fails for a new or acquired account
- You need sweep results to distinguish checked and clean from not checked

## Not for this skill when
- The account was checked and genuinely has no idle resources - verify the coverage list to be sure
- The role assumption fails for a deliberately excluded account - document the exclusion explicitly
- The sweep covers one account only by design - then the scope statement should say so

## Variant phrasings
- idle sweep skipped account role assumption failed
- agent reported all clean but never checked acquired account
- how to make cost sweep fail loudly on unreachable accounts
- cross account assume role silent failure cost audit

## Why it happens
Acquired accounts come with their own IAM setup, and the trust relationship the agent relies on does not exist there yet. Most SDK assume-role calls raise an exception that is easy to catch and log at debug level - and a sweep that catches the exception and continues will happily report all clean for an account it never saw. The bug is not the failed assumption; it is treating failure as success.

## Edge cases
- The acquired account may be in a different organization with its own payer. Sort out the billing relationship before assuming the sweep should cover it.
- Trust policies often restrict by external ID. Make sure the agent is configured with the right external ID for the acquired account.
- After fixing trust, historical data for the skipped period is still missing. Backfill the first sweep or annotate the gap so trends are not misleading.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_DryuDVpxYaU9FnPGWKUoIA
