> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/unified-identities/aws-identities/identity-center.md).

# Identity Center

The Identity Center page provides the enumerated AWS IAM Identity Center instance for the organization. The list contains the Instance ARN, Instance ID, Status, Identity Store ID, Account ID, Tier, Risk Score, Exposure Point and Issue Counts.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-fc0b8e4de5b23a288e96aa6c6ef5cbea58b8fe27%2Faws-identity-center.png?alt=media" alt=""><figcaption><p>Identity Center</p></figcaption></figure>

## Identity Center Details

Details page contains the Risk Score of the instance, Exposure Point, Information and Issues panes.

{% hint style="info" %}
IAM Identity Center is the control plane for workforce access across the organization. An organization has one instance, hosted in the management account or a delegated administrator. Forestall collects it once, from that account.
{% endhint %}

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-6f06dab276a72d0171241d1ea7d2ec07431c6338%2Faws-identity-center-details.png?alt=media" alt=""><figcaption><p>Identity Center Details</p></figcaption></figure>

## Information

Information Pane contains Details and Permission Sets tabs.

## Details

Details tab contains attributes below about the Identity Center instance object.

| Attribute         | Description                                                                |
| ----------------- | -------------------------------------------------------------------------- |
| Instance ARN      | The ARN of the Identity Center instance.                                   |
| Instance ID       | The Identity Center instance identifier (e.g., `ssoins-1234567890abcdef`). |
| Status            | The instance status.                                                       |
| Identity Store ID | The identity store bound to the instance (e.g., `d-1234567890`).           |
| Account ID        | The account that hosts the instance (management or delegated admin).       |
| Object ID         | The unique identifier of the instance object.                              |

## Permission Sets

Permission Sets tab lists every permission set defined in the instance. Each permission set becomes an assumable IAM role in the accounts it is provisioned to.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-db6a01849203537b870bfeb315d03883548df9bb%2Faws-identity-center-permission-sets.png?alt=media" alt=""><figcaption><p>Permission Sets</p></figcaption></figure>

## Issues

Issues pane contains identified security issues on the Identity Center instance object.
