> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/unified-identities/aws-identities/organizational-units.md).

# Organizational Units

The Organizational Units page provides a list of enumerated AWS Organizations organizational units (OUs). The list contains the OU ID, Name, Parent ID, Organization ID, ARN, Risk Score, Exposure Point and Issue Counts.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-27e8c2bfafb10e4b89cbbfbfa63abd647673d618%2Faws-organizational-units.png?alt=media" alt=""><figcaption><p>Organizational Units</p></figcaption></figure>

## Organizational Unit Details

Details page contains the Risk Score of the OU, Exposure Point, Information and Issues panes.

{% hint style="info" %}
OUs form the account hierarchy: an organization contains OUs, OUs nest inside other OUs, and accounts sit under a root or an OU. Service Control Policies attach to OUs, so an OU is the boundary an SCP applies to. The full tree — Organization → OU → OU → Account — is visible on the Organization details page and in the Graph.
{% endhint %}

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-079ab5e04b23c3b253ee1cf24f4013f0d7b579da%2Faws-organizational-unit-details.png?alt=media" alt=""><figcaption><p>Organizational Unit Details</p></figcaption></figure>

## Information

Information Pane contains the Details and Accounts tabs.

## Details

Details tab contains attributes below about the AWS Organizational Unit object.

| Attribute       | Description                                                                  |
| --------------- | ---------------------------------------------------------------------------- |
| OU ID           | The unique identifier of the organizational unit (e.g., `ou-abcd-12345678`). |
| Name            | The organizational unit name.                                                |
| Parent ID       | The ID of the parent root or OU that contains this OU.                       |
| Organization ID | The identifier of the AWS Organization the OU belongs to.                    |
| ARN             | The Amazon Resource Name of the organizational unit.                         |
| Object ID       | The unique identifier of the OU object, equivalent to the OU ID.             |

## Accounts

Accounts tab lists the AWS accounts that sit directly under this organizational unit. Accounts in a nested OU are listed on that OU, not here.

| Attribute  | Description                                 |
| ---------- | ------------------------------------------- |
| Name       | The account name.                           |
| Account ID | The 12-digit AWS account identifier.        |
| Status     | Whether the account is active or suspended. |

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-8d05a8d54361eccce486e3f1cf6bd4d8f19b8179%2Faws-organizational-unit-accounts.png?alt=media" alt=""><figcaption><p>Accounts</p></figcaption></figure>

## Issues

Issues pane contains identified security issues on the AWS Organizational Unit object.
