AWS Audit and Git Governance
Budget: $250 – $750 USD
AWS Environment & Git Workflow Auditor (High Volume Site Discipline)
AWS + Git discipline + environment auditing - US Citizens only
1. Git / Source Control Discipline
• Daily commits required before end of shift.
• Commit messages must be meaningful.
• No private or alternate repositories permitted.
• No local only work beyond same day development.
• Branch naming must follow a simple enforced pattern.
• All merges must be clean and conflict free.
• Weekly tag or release marker for traceability.
• CEO receives a simple weekly Git sync confirmation.
2. AWS Access & Security
• IAM roles must be minimal and correct.
• No wildcard permissions (*).
• No unused roles, keys, or policies.
• All access changes must be logged.
• Developer performs corrections within his role permissions.
• Auditor guides CEO through superuser level corrections live.
• Auditor does NOT perform superuser changes himself.
3. Environment Transparency
• All active resources must be visible and documented.
• No hidden services, buckets, repos, or pipelines.
• No unapproved third party integrations.
• No credentials stored outside AWS Secrets Manager.
• No environment drift — everything must match the documented architecture.
4. Developer Workflow Expectations
• Developer must be reachable via Zoom/Meet during scheduled audit windows.
• Developer performs all corrections within his permission scope.
• Developer provides proof of corrections (screen share, logs, commit IDs).
• Developer does NOT bill for delays or personal events.
• Developer does NOT expand scope or claim “development work.”
• Developer does NOT request additional hours for audit related corrections.
5. Auditor Workflow Expectations
• Auditor identifies corrections, gives instructions, then disconnects.
• Auditor does NOT stay online while developer works.
• Auditor returns only to verify corrections.
• Auditor stays online ONLY when guiding CEO through superuser AWS changes.
• Auditor does NOT perform development.
• Auditor does NOT expand scope.
• Auditor does NOT upsell or propose ongoing work.
6. Verification & Documentation
• Every correction must be verified by the auditor.
• Final deliverable is a tight bullet point procedure (like this), not a book.
• Final deliverable includes a correction ledger:
o Corrections made by developer
o Corrections made by CEO (superuser AWS)
o Corrections made by auditor (only when required)
o Final deliverable includes a cooperation and ability to work team hours when final team is established. (1 contractor); technical capability assessment.
AWS + Git discipline + environment auditing - US Citizens only
1. Git / Source Control Discipline
• Daily commits required before end of shift.
• Commit messages must be meaningful.
• No private or alternate repositories permitted.
• No local only work beyond same day development.
• Branch naming must follow a simple enforced pattern.
• All merges must be clean and conflict free.
• Weekly tag or release marker for traceability.
• CEO receives a simple weekly Git sync confirmation.
2. AWS Access & Security
• IAM roles must be minimal and correct.
• No wildcard permissions (*).
• No unused roles, keys, or policies.
• All access changes must be logged.
• Developer performs corrections within his role permissions.
• Auditor guides CEO through superuser level corrections live.
• Auditor does NOT perform superuser changes himself.
3. Environment Transparency
• All active resources must be visible and documented.
• No hidden services, buckets, repos, or pipelines.
• No unapproved third party integrations.
• No credentials stored outside AWS Secrets Manager.
• No environment drift — everything must match the documented architecture.
4. Developer Workflow Expectations
• Developer must be reachable via Zoom/Meet during scheduled audit windows.
• Developer performs all corrections within his permission scope.
• Developer provides proof of corrections (screen share, logs, commit IDs).
• Developer does NOT bill for delays or personal events.
• Developer does NOT expand scope or claim “development work.”
• Developer does NOT request additional hours for audit related corrections.
5. Auditor Workflow Expectations
• Auditor identifies corrections, gives instructions, then disconnects.
• Auditor does NOT stay online while developer works.
• Auditor returns only to verify corrections.
• Auditor stays online ONLY when guiding CEO through superuser AWS changes.
• Auditor does NOT perform development.
• Auditor does NOT expand scope.
• Auditor does NOT upsell or propose ongoing work.
6. Verification & Documentation
• Every correction must be verified by the auditor.
• Final deliverable is a tight bullet point procedure (like this), not a book.
• Final deliverable includes a correction ledger:
o Corrections made by developer
o Corrections made by CEO (superuser AWS)
o Corrections made by auditor (only when required)
o Final deliverable includes a cooperation and ability to work team hours when final team is established. (1 contractor); technical capability assessment.