Upcoming Workshop: Citizen Developer Agentic Software Factory on AWS

Register Here!

Your AI agent does not need cloud credentials.

Coding agents like Claude Code can now plan and change infrastructure. The usual shortcut is to give the agent an AWS key or a broad IAM role, which gives it the reach of the person who set it up. Massdriver gives the agent a scoped token instead, and keeps the cloud credentials on its own side of the boundary.

The agent may plan and propose in non-production. It cannot deploy anywhere, and it cannot touch production at all.

Why a cloud key in an agent is a production risk

A cloud credential does not know who is using it. An agent with an access key or an assumed role can create, change, or delete anything the role allows, in every environment the role reaches, and the cloud audit trail shows the role, not the agent. Narrowing IAM per agent and per environment becomes a second permission system the platform team maintains by hand.

How the access is split

01

The agent holds a Massdriver token

The token belongs to a service account with an expiry you set. The agent receives it through the Massdriver MCP server’s environment and never sees a cloud key.

02

Policy decides what the token may do

The service account belongs to a group, and the group’s attribute-based policies say which actions it may take on which environments, projects, or teams.

03

Massdriver holds the cloud credentials

AWS, Azure, and GCP credentials stay in Massdriver, which uses them only for deploys the policy allows.

04

Production needs a person

Proposing a change and deploying it are separate permissions, so an agent can propose a production change while a person with deploy permission decides.

The configuration

Field names are the API’s. Values are illustrative. Revoking the token or removing the service account from its group ends the agent’s access, with no cloud IAM change.

The agent gets the token through the MCP server’s environment. It never sees a cloud key.
The agent may plan and propose in non-production. It cannot deploy anywhere, and it cannot touch production at all.
The agent proposes a production change. A platform approver sees the plan diff and the policy result, then approves or rejects.

Watch Architect work inside those controls

A two-minute demo: a developer describes an app in Claude Code, and Architect builds it only from the approved catalog, under the same policy as every other change.

In production