Onboarding

Get started with qrie - initial setup and inventory generation

Prerequisites
Before you begin, ensure you have the following:
QOP Account Deployed
Qrie engineers have set up your dedicated QOP (Qrie On-Premises) account with UI access
AWS Account IDs
12-digit AWS account IDs for accounts you want to monitor
Step 1
Generate Initial Inventory
Inventory is the foundation - policies need resources to evaluate
Add accounts via the Management UI + onboarding script:
1.Navigate to Management page → click Add Accounts → paste one or more AWS account IDs.
2.Accounts are added with "Pending" status. Click the info button (ℹ️) next to a pending account.
3.Download onboard.sh + customer_bootstrap.yaml. Copy the prefilled script command.
4.Run the script with credentials for the customer account. It deploys mandatory us-east-1 first (IAM roles + IAM-events rule + us-east-1 regional rules), then auto-detects opted-in regions and deploys regional rules in parallel.
5.Hit Refresh in the dialog. Status table shows green dots once stacks land.
6.Inventory scan kicks off automatically once the cross-account role becomes assumable.
What happens:
  • •Scans all supported services (S3, EC2, IAM, RDS, Lambda, CloudTrail, KMS) across all your AWS accounts
  • •Stores resource configurations in the qrie_resources DynamoDB table
  • •This is a bootstrap scan - drift metrics are NOT updated
Expected Duration
5-15 minutes depending on resource count
Step 2
Check Inventory Completion
Verify that inventory generation has finished successfully
Method 1: Dashboard

Navigate to the Dashboard and check:

  • •Resources count should be greater than 0
  • •Last Inventory Scan timestamp should be recent
Method 2: Inventory Page

Visit the Inventory page to see all discovered resources

Method 3: Command Line
aws dynamodb scan --table-name qrie_resources --select COUNT --region us-east-1 --profile qop
Step 3
Launch Your First Policies
Once inventory is complete, you can start launching policies

Navigate to the Management page to:

  • •Browse available policies by category (IAM, S3, EC2, etc.)
  • •Click "Launch" on policies you want to activate
  • •Configure scope (which accounts to monitor)
  • •Optionally customize severity and remediation steps
Troubleshooting
Common issues and solutions
No resources found after inventory scan

Check:

  • • CloudFormation stack deployed successfully in customer account
  • • EventBridge rules are correctly forwarding events to QOP account
  • • IAM role QrieReadOnly-{AccountId} exists with SecurityAudit policy (created by us-east-1 deploy)
  • • Account shows "Active" status in Management page (click refresh button if pending)
Inventory scan takes too long
Large AWS environments (1000+ resources) may take 15-20 minutes. This is normal. You can monitor progress in CloudWatch logs for the qrie_inventory_generator Lambda.
Permission errors during scan
Ensure the Lambda execution role has cross-account assume role permissions and the customer account IAM roles trust the QOP account.