Choose your path
Find the right starting point for what you want to do with AWS Security Agent. Use the table below to match your goal to a task, then go directly to that page. If you’re new to AWS Security Agent, read What is AWS Security Agent? first for a quick overview.
| I want to… | Who | Start here |
|---|---|---|
|
Understand what AWS Security Agent does before setting it up |
Everyone |
|
|
Set up the service and create an Agent Space |
Admin |
|
|
Test my live or deployed application for exploitable vulnerabilities |
User |
|
|
Scan my source code for vulnerabilities and policy violations |
User |
|
|
Model how my application could be attacked (STRIDE) |
User |
|
|
Get security feedback on a design before I write code |
User |
|
|
Scan code without leaving my IDE (Kiro or Claude Code) |
Developer |
|
|
Scan only my changed lines before merging |
Developer |
|
|
Get automatic security comments on pull requests and merge requests |
Admin |
|
|
Review findings and decide what to fix first |
User |
Note
AWS Security Agent uses three roles, which you can identify by the interface you work in: Admin works in the AWS Management Console (setup and configuration), User works in the web application (running assessments and reviewing findings), and Developer works in GitHub or an IDE such as Kiro or Claude Code. A single person can hold more than one role. For full definitions, see How AWS Security Agent works.