When using the AWS Organization integration workflow, you might be seeing a warning in the Inventory page, AWS Organization, for certain accounts labeled "ASSUME_ROLE." This indicates that your AWS child account is missing the proper vanta-auditor role required.
Procedure
Navigate to IAM for the connected AWS management account
Locate the role and policy that were created for the vanta integration (role is typically named "vanta-auditor" and policy typically "vantaAdditionalPermissions")
The same role needs to be created in the subaccounts with VantaAdditionalPermissions policy as well as the SecurityAudit policy attached
Ensure that the trust relationship is set up the same way as well. These IDs will be the same for all of your connected accounts:
