Updated on 2026-04-16 GMT+08:00

Overview

Functions

A resource aggregator enables you to aggregate resource configurations and compliance data from multiple accounts or an organization for centralized data query.

You can only view aggregated resources and their compliance data instead of modifying resource data. For example, you cannot use a resource aggregator to deploy rules or access snapshots from a source account.

You can only use aggregators to query or view resource data from source accounts. If you need to modify or delete resources, go to related service consoles.

Constraints

The resource aggregator is subjective to the following constraints:

  • Up to 30 account-level aggregators can be created in an account.
  • An account-level aggregator can aggregate data from up to 30 source accounts.
  • You can add, update, and delete up to 1,000 source accounts every 7 days for an account-level aggregator.
  • Up to 1 organization-level aggregator can be created in an account.
  • You can only create one organization-level aggregator within 24 hours. If you create and then delete an organization-level aggregator, you cannot create one within 24 hours.
  • To aggregate resource configuration data from source accounts, the resource recorder in each source account must be enabled.
  • Organization-level aggregator will only aggregate data from member accounts that are in the normal state.

Resource and compliance data from a source account is synchronized to the aggregator only when the resource recorder is active on that source account. The following conditions govern data aggregation behavior:

  • Initial state: If the resource recorder has never been enabled on a source account, the aggregator cannot retrieve any resource or compliance data from that account.
  • Partial monitoring scope: If the resource recorder is enabled but restricted to a subset of resources, the aggregator collects resource data compliance data only for those specific selected types.
  • Discontinuation: If the resource recorder is disabled after being active, the aggregator automatically deletes all previously collected resource and compliance data associated with that source account.

For details about how to enable and configure the resource recorder, see Configuring the Resource Recorder.

Setting Up An Aggregator

To collect resource data from source accounts, perform the following operations:

  1. Create an aggregator. For more details, see Creating a Resource Aggregator.
  2. Enable the resource recorder from every source account. For more details, see Configuring the Resource Recorder.
  3. Authorize the aggregator account to collect resource configurations and compliance data from source accounts. For more details, see Authorizing an Aggregator Account.
  4. View resource configurations and compliance data aggregated. For more details, see Viewing Aggregated Rules and Viewing Aggregated Resources.

Basic Concepts

Source Account

A source account is an account from which Config aggregates resource configurations and compliance data. A source account can be an account or an organization.

Aggregator

An aggregator is a kind of Config resource allowing you to collect resource configuration and compliance data from multiple resource accounts.

Aggregator Account

An aggregator account is an account used to create an aggregator.

Authorization

Authorization is the process of granting an aggregator the permission to collect resource configurations and conformance data from source accounts. An organization-level aggregator, however, does not need authorization to collect data from member accounts.