> For the complete documentation index, see [llms.txt](https://copilot-docs.bugbase.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://copilot-docs.bugbase.ai/enterprise/how-to-trigger-a-cloud-assessment/configure-cloud-assessment.md).

# Configure the Assessment

Select cloud test categories, safeguards, and rollback behavior.

Open **Modules -> Internal Assessment -> Run Assessment**. Choose **Assessment** for an existing cloud inventory or **Discovery + Assessment** to refresh inventory first.

## Target and Agent

Select the discovered AWS account, Azure subscription/resource group, or GCP project and the connected agent on the approved cloud VM. The agent's attached workload identity performs provider operations.

The selected categories and that identity's permissions must both match the approved scope.

## Test Categories

Disable every category that is not authorized.

| Category                            | Typical coverage                                                           |
| ----------------------------------- | -------------------------------------------------------------------------- |
| Cloud Identity Privilege Escalation | Roles, policies, identities, federation, and delegation                    |
| Cloud Credential Access             | Tokens, keys, signed URLs, secrets, and credential stores                  |
| Cloud Data Exposure                 | Storage, databases, backups, messages, logs, and secrets                   |
| Cloud Configuration Exposure        | Public management, metadata, encryption, and trust boundaries              |
| Cloud Workload Execution            | Commands, builds, functions, containers, startup actions, and code updates |
| Cloud Authentication Bypass         | IAM conditions, sessions, tokens, devices, and authentication policy       |
| Cloud Lateral Movement              | Federation, hybrid identity, synchronization, and delegated access         |
| Cloud Policy Misconfiguration       | Policies, bindings, encryption, event sources, and access settings         |
| Cloud Network Control               | Firewalls, security groups, NSGs, DNS, peering, routes, and remote access  |
| Cloud Persistence                   | Keys, grants, scripts, devices, signed access, and management links        |
| Cloud Defense Evasion               | Logging, diagnostics, flow logs, security services, sinks, and locks       |
| Cloud Destructive Impact            | Deletion, disablement, quotas, keys, objects, recovery, and disruption     |

## Optional Controls

* **Validate pre-existing vulnerabilities** is for retesting stored findings.
* **Regional monitoring coverage** should remain empty unless an approved unused-region test has prepared monitoring inventory.
* **Rollback supported changes** restores only changes that implement automated rollback. It does not replace the engagement cleanup plan.
* **RCE safeguards** should match the authorization and the desired behavior for already-compromised nodes.
* Runtime limits stop remaining work after the configured duration.

{% content-ref url="/pages/ArSzYQDa8xnxlD7aLJmK" %}
[Advanced Settings](/enterprise/cloud-assessment-reference/advanced-cloud-assessment-settings.md)
{% endcontent-ref %}

## Final Review

Before starting, confirm:

* provider scope and connected agent;
* attached workload identity and temporary permissions;
* enabled categories;
* retest and regional-monitoring settings;
* rollback and RCE safeguards;
* runtime and schedule;
* cleanup owner and stop conditions.

Use **Start run** for immediate execution or **Schedule run** for the configured schedule.
