Add TAP Role Mappings
A TAP Role Mapping connects the TAP Dashboard to an IAM Role in the underlying AWS Account.
After a TAP Role Mapping exists, you can assign it to a Combine User. The Combine User can then sign in to the underlying AWS Account's AWS Console through TAP Dashboard federation.
Several API integrations that are specific to US Government sponsored Partitions also use TAP Role Mappings.
When to Add a TAP Role Mapping
Combine initializes each Combine Deployment with a set of default TAP Role Mappings. In most cases these are sufficient, but you might need to add TAP Role Mappings in the following cases:
- You are adding a custom IAM Role to Combine (based on your Sponsor's direction). Add a TAP Role Mapping for this IAM Role so that your Users can assume it into the AWS Console.
- You are adding a Follower Account to a Leader Account in a multiple account topology. Combine initializes the Follower Account with a set of default TAP Role Mappings in the Leader Account. However, if you manually add an existing Combine account as a Follower Account, you may need to add them manually. (See Add Follower Account.)