Skip to content
AWS Cognito · multi-account

One secure workspace for every Cognito user pool

Give your platform team one place to manage Cognito users, groups, and access across AWS accounts—without sharing console credentials.

Start an organization, connect an AWS account, then invite your team.

userpools.com
Admin

Production / User pools

Customer identity

UserGroupStatus
maya@acme.ioAdministratorsActive
sam@acme.ioSupportActive
alex@acme.ioAuditorsActive
Role-scoped access · Activity recorded
Get started in minutes

Built around the way your team already works

  1. 01

    Create or join an organization

    Start your workspace or use an invite from your team.

  2. 02

    Connect AWS accounts securely

    Use a dedicated cross-account role and external ID.

  3. 03

    Give each person scoped access

    Share the accounts and user pools they need—nothing more.

Operations without console hopping

Everything your Cognito operations team needs

A focused workspace for the tasks that become difficult when pools and teams are spread across AWS accounts.

Multi-account user pools

Register vendor AWS accounts and switch between Cognito user pools from one portal — no console hopping.

Secure cross-account access

Connect with IAM role assumption and external ID. Trust policies stay in your control.

Role-based access control

Admin, Maintainer, and Auditor roles with user-pool-level sharing so teams get exactly the access they need.

User & group management

Browse users, edit attributes, manage groups, and inspect pool settings from a unified interface.

Team sharing

Invite portal users to accounts or individual user pools. Admins own billing; maintainers share pools with auditors.

Portal user directory

Pick teammates from your app’s Cognito user pool when granting access — no manual user IDs.

Controlled access

Give auditors access without AWS account logins

Keep console credentials out of your review process. Invite people to the precise user pools they need and preserve a clear record of the changes made in your portal.

One portal login

Auditors sign in to this app only — no separate IAM users, console access, or credentials in each vendor AWS account.

Read-only by design

The Auditor role can view users, groups, and pool settings but cannot change attributes, membership, or pool configuration.

Per user pool scope

Share only the user pools under review. Compliance and security teams see exactly what they need — nothing more.

Audit-ready access model

Every grant is tied to a portal user, account, and user pool with a clear role — built for reviews, not day-to-day operations.

Access that matches how your team works

Three account roles plus platform super-admin for break-glass support.

Admin

Account-wide

Registers vendor accounts, manages billing, IAM setup, and full access to every user pool on the account.

Maintainer

Per user pool

Read and write on shared user pools. Can invite maintainers and auditors to pools they manage.

Auditor

Audit-ready

Read-only access to shared user pools via the portal — review users, groups, and pool details without AWS console logins.

Ready to manage your user pools?

Create your organization, connect your first AWS account, and invite the people who need access.

Create your workspace