Table of contents

Access the AWS console

đź’ˇ Before you can access something in AWS, you need to set up your AWS account.

In our AWS environment, you temporarily “assume a role” for a sub-account. For example, you can assume the role of “administrator on integration” (which gives you all the power), or “power user on production” (which gives you a more limited set of rights). By default, if you try to click on anything in the AWS console you’ll likely see “You are not authorized”. This is because you’re still in your default account without any permissions.

👉 Sign in to AWS GDS account first

Remember that you’ll have to have been added to the appropriate group first.

1. Click “Switch Role” in the top right corner.


2. Fill in account and role

Options for “Account”:

  • govuk-infrastructure-production
  • govuk-infrastructure-staging
  • govuk-infrastructure-integration
  • govuk-infrastructure-test

Options for “Role”:

  • govuk-administrators
  • govuk-powerusers
  • govuk-platformhealth-powerusers
  • govuk-users


3. Switch to other roles

If you’ve set all of the roles up, they are then easily accessible from the “Switch Role” menu, without having to type in the details every time. (Roles do not persist across browsers, you have to set them up individually for every browser.)


If you set the roles up with nicknames and different colours, it’s easy to tell which role you are in. Otherwise, click on your username in the top right corner and it will tell you which role you have assumed on which account.

gds-users-show-role gds-users-show-account

This page was last reviewed . It needs to be reviewed again by the page owner #govuk-2ndline.