Skip to content

Documentation

StaleSweep is a read-only AWS scanner that finds stale, idle, and unused resources across your accounts and shows you what they cost. Pick a section to get started.

Tip: The one thing to know up front: StaleSweep is strictly read-only. The scanning role you deploy can only describe and list resources — it can never modify, stop, or delete anything. Every cleanup action stays in your hands.

Guides

AWS account setup

Connect a standalone account or a whole AWS Organization with a one-click, read-only CloudFormation deploy.

SSO setup

Sign in with Google/Microsoft, or connect Okta, Entra ID, or any SAML 2.0 identity provider for your team.

Scan scheduling

Run scans automatically — daily through bimonthly — and follow progress and results in the app.

Exception rules

Suppress intentional resources with rules, tags, or one click, without disabling whole detectors.

What we detect

The stale, idle, and unused resource patterns the scanner looks for, and how it avoids false positives.

Results, savings & exports

How findings, estimated savings, realized savings, and CSV export work.

Security risk scoring

How each finding is scored for security exposure, what the severity bands mean, and what the score deliberately does not claim.

Cost insights setup

Turn on Cost & Usage Report (CUR) ingestion for real AWS spend — bill breakdown, cost anomalies, and spend joined to your findings.

Slack report delivery

Post cost-report summaries and the full PDF to Slack channels, on demand or on a schedule.

Email report delivery

Email cost-report summaries with the PDF attached to any recipient, on demand or on a schedule.

AI access (MCP)

Connect Claude or any Model Context Protocol client to your account with a read-only credential, and control what it may read.

Security & privacy

Read-only access, External IDs, tenant isolation, session security, and audit logging.

Troubleshooting

Fixes for the most common connection and scan issues.