# Cloud IAM Import: Explained

> How ZopNight imports IAM users, groups, and roles from AWS, GCP, and Azure with review before apply, curated policy translation, and idempotent re-import.

Source: https://zop.dev/learn/cloud-iam-import
Published: 2026-07-01 · Author: avinash-gaurav · Tags: zopnight, learn

---

Cloud IAM import brings the users, groups, and roles that already exist in your AWS, GCP, or Azure account into ZopNight so access maps to how your cloud is actually organized. It is admin-triggered and review-before-apply: nothing is written until you approve it, because auto-applying cloud changes would silently grant access.

This guide keeps the theory short and spends most of its length on what you can actually do. Every recommendation here is one ZopNight can help you execute, starting from a read-only connection.

## Passive discovery, admin-triggered write

IAM principals show up in ZopNight inventory on the normal read-only discovery sweep. The identity write to users, teams, roles, and mappings happens only when an admin clicks Apply in the wizard. That separation is deliberate: discovery is safe and read-only, and granting access is an explicit action.

## Curated, security-reviewed translation

Known cloud policies and roles map to a curated ZopNight policy set, and custom roles are action-translated. Org-management grants such as role, user, assignment, and organisation are never auto-imported, even for administrator roles like AdministratorAccess or Owner. Conditional or subtractive rules that cannot be translated safely are flagged rather than widened.

## Needs Attention and idempotency

Anything unrecognised lands in Needs Attention until an admin resolves it, and missing emails can be filled one by one or by CSV. Re-import is idempotent, keyed on the cloud-native identifier, and Disconnect cleanly removes everything imported from that account while preserving links shared with other accounts.

## Key takeaways

- Discovery is read-only; the identity write requires an explicit Apply.
- Org-management grants are never auto-imported, even for admin roles.
- Custom roles are action-translated; unsafe rules are flagged, not widened.
- Re-import is idempotent and Disconnect is clean.

## Where ZopNight fits

ZopNight turns this from reading into doing. It ships 490 built-in audit rules across AWS (216), GCP (127), and Azure (147), 124 of those recommendations are wired to act end to end, 28 one-click and 96 guided, and it starts read-only so you can see the opportunity before you act on any of it. The most direct place to begin is scheduling non-production resources to your working hours, which is covered in the [FinOps](https://zop.dev/learn/finops) guide and shown concretely for [AWS EC2](https://zop.dev/zopnight/aws/ec2).

## How ZopNight schedules non-production resources

The loop that does this is deliberately mechanical, and it starts read-only. You connect your cloud provider with a read-only role, and ZopNight discovers every non-production resources across your regions and accounts. It records a per-action permission verdict for each one, so you can see where it can list a resource but not yet stop it, and you review that inventory, filter it by status or type, and search for the specific resources you care about before anything is scheduled.

Scheduling itself is a cron you write once in plain terms, stop at 7 PM, start at 8 AM on weekdays, pinned to your timezone so the jobs fire at local business hours rather than UTC. A weekly 24-hour grid shows the schedule visually so you catch gaps and overlaps before you save, and an estimate of active versus inactive hours appears before you commit. Resources attach individually or bundle into groups like "dev-cluster" or "staging-db" so a whole environment follows one cadence.

Actions run in dependency order, so a database comes up before the app server that depends on it. When something needs to stay up, an override forces a non-production resources ON or OFF for a defined window, carries a reason so teammates understand why it exists, and expires automatically so nothing is left running by accident. If a start or stop fails, ZopNight retries up to three times and falls back to a dead-letter queue rather than silently dropping the action, and every state change lands in an audit trail that records whether a schedule, an override, or a specific user triggered it.

## Getting started

Getting started is intentionally low-stakes:

- Connect your cloud provider with a read-only role. Nothing is scheduled or changed at this stage.
- Let ZopNight discover your non-production resources and review exactly what it found, filtered by account, region, and status.
- Create a schedule in your timezone and attach the non-production resources or groups you want it to cover.
- Watch the first cycle run, with Slack, Teams, or Google Chat notifications on every start, stop, and failure, then layer in idle cleanup and guided rightsizing.

Production stays excluded by default throughout, and because discovery and recommendations are read-only, you can prove the value before you enable a single action.

## Frequently asked questions

### Can importing IAM grant access by accident?

No. Nothing is written until Apply, and org-management grants are never auto-imported even for administrator roles.
