Table of contents

AWS accounts

Access the AWS console

💡 Before you can access something in AWS, you need to set up your AWS account.

In our AWS environment, you temporarily “assume a role” for a sub-account. For example, you can assume the role of “administrator on integration” (which gives you all the power), or “power user on production” (which gives you a more limited set of rights). By default, if you try to click on anything in the AWS console you’ll likely see “You are not authorized”. This is because you’re still in your default account without any permissions.

👉 Sign in to AWS GDS account first

Remember that you’ll have to have been added to the appropriate group first.

1. Click “Switch Role” in the top right corner.


2. Fill in account and role

Options for “Account”:

  • govuk-infrastructure-production
  • govuk-infrastructure-staging
  • govuk-infrastructure-integration
  • govuk-infrastructure-test
  • govuk-tools

Options for “Role”:

  • govuk-administrators
  • govuk-internal-administrators
  • govuk-powerusers
  • govuk-platformhealth-powerusers
  • govuk-users


3. Switch to other roles

If you’ve set all of the roles up, they are then easily accessible from the “Switch Role” menu, without having to type in the details every time. (Roles do not persist across browsers, you have to set them up individually for every browser.)


If you set the roles up with nicknames and different colours, it’s easy to tell which role you are in. Otherwise, click on your username in the top right corner and it will tell you which role you have assumed on which account.

gds-users-show-role gds-users-show-account

This page was last reviewed on 17 May 2019. It needs to be reviewed again on 17 November 2019 by the page owner #govuk-2ndline .
This page was set to be reviewed before 17 November 2019 by the page owner #govuk-2ndline. This might mean the content is out of date.