Linking AWS Organizations as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The AWS Organizations connector syncs accounts, organization, organizational units, and more into the PostHog data warehouse, so you can analyze them alongside your product data.
Prerequisites
Credentials that can read the data you want to sync. PostHog only reads data, so read access is enough.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
Sync your AWS organization structure, so cost and usage data can be read by account name, organizational unit, and tag.
Create an IAM user or role with the organizations:DescribeOrganization, organizations:ListAccounts, organizations:ListRoots, organizations:ListOrganizationalUnitsForParent, organizations:ListPolicies and organizations:ListTagsForResource permissions, then paste its access key ID and secret access key. Add a session token too if you are using temporary credentials.
Use a key from the management account or from a member account that is a delegated administrator. Keys from other member accounts can only read the organization table.
AWS Organizations is a global service, so there is nothing to pick a region for. This source syncs the accounts, organizational units, and policies in the standard AWS partition.
You'll be asked for:
- AWS access key ID: for example
AKIA.... - AWS secret access key
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
All AWS Organizations tables are full refresh. Each sync replaces the contents of the table.
Configuration
| Option | Description |
|---|---|
AWS access key IDType: text Required: True | |
AWS secret access keyType: password Required: True | |
AWS session tokenType: password Required: False | Only for temporary credentials. Session tokens expire after a few hours, so scheduled syncs will fail once the token expires. Use a permanent access key (starts with AKIA) for recurring imports. |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
accounts | Every AWS account in the organization, with its name, email, state, and the time it joined. | Full refresh | — | — |
organization | The organization itself: its ID, feature set, and management account. One row per sync. | Full refresh | — | — |
organizational_units | Organizational units in the account hierarchy, each with the parent it sits under. | Full refresh | — | — |
policies | Policies in the organization, one row per policy, across every policy type the organization supports. | Full refresh | — | — |
resource_tags | Tags attached to accounts, roots, organizational units, and policies. One row per tag. | Full refresh | — | — |
roots | Roots of the organization, with the policy types enabled on each. | Full refresh | — | — |
Troubleshooting
- If the connection fails with an authorization error, the AWS access key ID is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
- If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.