New Savings Proposals: approve, test and roll back cost changesLearn more Sign in|Talk to a cloud engineer

Architecture diagrams drawn from the scan

Blueprint lays out regions, VPCs, subnets and the services inside them, using the same read-only scan that produces your findings. Export it for a design review and it matches what is running today.

What you're watching
  1. 1
    Draw from the scan

    Blueprint reads 84 resources and lays out eu-west-1, prod-vpc and the public, private and data subnets from where each one runs.

  2. 2
    Spot the risk on the tiles

    bastion in the public subnets carries a port 22 open flag. customer-exports in the data subnets carries a PII label.

  3. 3
    Export as SVG

    checkout-blueprint.svg exports with 11 tiles and 5 boundaries, ready to drop into a design doc.

Who does thisStaff engineer or architect, reviewed with the security engineering leadWhat you getA design-review diagram that matches production on the day it was exported.
Drawing modes
0
Graph, Blueprint and Lanes
Lenses
0
Traffic, Apps, Types, Networks, Services
Exports
PNG · SVG
for design docs and reviews
Source
Scan
layout computed from where resources live

Your cloud changes daily, your diagram does not

Design reviews, onboarding and incident calls all run on a picture someone drew months ago.

Accuracy

Hand-drawn diagrams go stale

What usually happens: The diagram was right the week it was drawn. Six months later it's missing two services and a VPC peering.

How CloudLens resolves it: Blueprint redraws from each scan, so the diagram changes when the account does.

Resolved
Reviews

Reviews stall on basic facts

What usually happens: Half of a threat-model session goes to working out whether the queue really sits in a private subnet.

How CloudLens resolves it: Subnet and VPC boxes come from where resources actually live, so the review starts from what's deployed.

Resolved
Security

Risk lives in another tool

What usually happens: The architecture doc shows clean boxes, and the exposure sits in a scanner export nobody attaches.

How CloudLens resolves it: Open ports, internet exposure and data classes are drawn on the tiles they belong to.

Resolved

Preparing a design review with Blueprint

Tom is planning to move payments out of the checkout service and needs an accurate starting diagram.

TBTom BeckerStaff engineer, Lumora Retail

Lumora Retail is a fictional company. The people, names and numbers are sample data.

    1
    Mon 11:00

    Starts from the front door

    He picks the checkout hostname in the Traffic lens. A few hundred resources in the account narrow to the services a checkout request actually reaches.
    2
    Mon 11:20

    Switches to Blueprint

    The same services appear inside the prod-core VPC, grouped into public, private and data subnets.
    3
    Mon 11:35PII

    Notices the data tier

    orders-db sits in the data subnet as expected, but its tile carries a PII label and a path from checkout-api. He adds that to the review as an open question.
    4
    Tue 09:00

    Exports PNG and SVG

    The SVG goes into the design doc and the PNG into the slides. Both show the lens and mode he had selected.
    5
    Two weeks later

    Reopens it after the split

    Once payments-api is deployed, Blueprint already shows the new service and its subnet, taken from the latest scan.
Design review next week?

Start from a diagram of what's actually deployed

The diagram your team never has to redraw

Atlas draws from the same read-only scan that powers findings, so the diagram and the risk describe the same estate.

Scope a diagram by how requests arrive

Pick a front door, such as a public hostname behind Route 53, CloudFront or API Gateway, and the diagram keeps only the tiles its requests touch. A crowded account becomes the handful of services behind checkout.
  • Public entry points listed
  • Only tiles on the request path
  • Internet-exposed markers
What you're watching
  1. 1
    Pick checkout.lumora-retail.example

    The diagram keeps 5 of 11 tiles: Route 53, checkout-cdn, checkout-lb, checkout-api and orders-db. Everything else dims.

  2. 2
    Switch to api.lumora-retail.example

    The request path changes to public-api, tickets-fn and support-tickets. A different front door leads to a different data store.

  3. 3
    Check images.lumora-retail.example

    Requests pass through image-cdn to image-resizer, which reaches customer-exports. That hop belongs on the review's list of questions.

Who does thisStaff engineer preparing a threat model, with a cloud security engineerWhat you getOne diagram per public hostname, showing only what its requests touch.

Regroup the estate around your question

Switch between Traffic, Apps, Types, Networks and Services. Tiles move into their new groups rather than redrawing, so you don't lose your place. Traffic keeps the Internet-exposed markers, so exposure is visible from the first view.
  • Apps by application tag
  • Networks by VPC and subnet
  • Services by AWS service
What you're watching
  1. 1
    Start from the Traffic lens

    Tiles sort into front doors, what sits behind them, and data. checkout-cdn and checkout-lb are marked Internet-exposed.

  2. 2
    Regroup by app and type

    The same tiles move into app: checkout, app: media and app: support, then into networking, compute, identity and data.

  3. 3
    Check Networks and Services

    Networks separates prod-vpc public and private subnets from regional services with no VPC. Services lists one group per AWS service.

Who does thisStaff engineer or platform lead preparing a design reviewWhat you getThe grouping that fits the review, built from the same eight resources every time.

Graph, Blueprint and Lanes for different reviews

More on the Security Graph
Graph shows relationships. Blueprint gives architecture-diagram density. Lanes reads left to right from internet-facing to data. Click any tile for its metadata, hierarchy and relations.
  • Graph: relationships
  • Blueprint: boundaries and tiles
  • Lanes: internet to private to data
What you're watching
  1. 1
    Click a tile in Graph mode

    checkout-api opens with its region, owner and hierarchy. It sits behind checkout-lb, runs as checkout-task-role and reaches orders-db.

  2. 2
    Switch to Blueprint

    The tiles move into Edge, Compute and Identity & data boxes, closer to a hand-drawn architecture diagram.

  3. 3
    Switch to Lanes

    The same tiles line up from Internet-facing through Private to Data, which is how most threat models read.

Who does thisStaff engineer or platform lead, depending on the reviewWhat you getThree layouts of one scan, so relationship, boundary and exposure questions share a source.

Diagrams you can put in a design doc

Service-level tiles

One tile per service with its type and name, at the density of a hand-made architecture diagram.

Real boundaries

Region, VPC and subnet boxes come from where resources actually live.

Risk on the picture

Open ports, internet exposure and data classes appear on the tiles they belong to.

PNG and SVG export

Put the current diagram in a design doc, a threat model or an audit pack.

Graph Blueprint Lanes PNG / SVG

About architecture diagrams

From the same read-only scan that builds the Security Graph. There is nothing to install and nothing to draw. The layout is computed from where resources live and how they connect.

The Traffic lens only treats entry points that route requests to workloads as front doors. Validation records and gateways without routes are left out.

Yes. Export the current view as PNG or SVG. The export reflects the lens and mode you have selected.

Get an accurate diagram of your own cloud

Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.