Cloud Account Attestation | Cloud Account Database

The document explains how cloud account owners complete the quarterly attestation process in Cloud Account Database. It covers finding accounts due for attestation, confirming each account is still needed, validating required contacts, reviewing synchronized cloud access, requesting closure for unused accounts, completing the attestation, and resolving common issues.

Before You Begin

Who can complete an attestation? Only someone listed as a current Owner contact for the account can complete its quarterly attestation.

A quarterly attestation confirms that an active cloud account is still needed and that its required contacts and synchronized cloud access are current. Complete each account separately.

Before starting, be prepared to:

  • Decide whether the account is still in use.
  • Review the Owner, Technical, Security, and Financial contacts.
  • Provide an @wisc.edu email address for any contact that must be added or corrected.
  • Review the people and permissions in the synchronized AWS, Azure, or GCP access list.
  • Use the applicable access-management KB to update access, if needed, before completing the attestation.
  • Request an access change or account closure instead of completing the attestation when the displayed information is incorrect.

Cloud Account Database is available at accounts.cloud-services.wisc.edu.

Find Accounts That Need Attestation

  1. Open Account Overview. Sign in to Cloud Account Database and select Account Overview.
  2. Review the TODO panel. The panel lists each account you own that needs a current quarterly attestation, including its cloud provider and attestation cycle.
  3. Select Review attestation. The link opens the account record at the Quarterly Account Attestation panel.

You may also receive an email with the subject Quarterly cloud account attestation required. One reminder can list multiple accounts you own. Each entry includes the account name, account ID, cost for the latest billed month, and a direct link to the account record.

Billing amount in the reminder. The amount provides context only. Review and attest the account based on whether it is still needed and whether its contacts and access are correct.

Confirm the Account Is Still in Use

Start with Step 1 in the attestation panel.

  • If the account is still needed, continue to the contact review.
  • If the account is no longer needed, select Request Account Closure instead of completing the attestation.

To request closure, confirm that required data has been backed up, enter the exact account ID, and select Submit Closure Request. The request creates an operational Jira request for Cloud Services; it does not immediately delete or close the cloud account.

Do not attest an unused account. After a valid closure request is recorded, the account leaves the attestation campaign while Cloud Services tracks the closure work.

Validate Required Contacts

In Step 2, review the contacts in this order: Owner, Technical, Security, and Financial.

Contact Status Overview
Status What to do
Ready Review the displayed name and email. Final validation will confirm the identity in Microsoft Entra.
Missing The card is highlighted in yellow. Select Add Contact, enter the @wisc.edu email address, and select Validate and Save.
Invalid The card is highlighted in red. Select Edit Contact, correct the @wisc.edu email address, and select Validate and Save.
  • Owner, Technical, and Financial each require one @wisc.edu email address that resolves uniquely in Microsoft Entra.
  • Security requires at least one contact and may contain multiple comma-separated @wisc.edu email addresses. Every address must resolve uniquely.
  • After a contact is saved, return to the attestation panel and review all four roles again.

Review Synchronized Cloud Access

In Step 3, confirm that every person, permission, and role in the AWS, Azure, or GCP access table is still appropriate. The panel identifies its data sources and shows that the access data refreshes every 24 hours.

If access must change, use the access-management KB shown in the panel and complete the appropriate access-management process. Do not complete the attestation while an incorrect person, permission, or role is still displayed.

Allow time for synchronization. Access changes may take up to 24 hours to appear in Cloud Account Database. Return to the account, review the refreshed list, and validate again before completing the attestation.

If the list is empty or does not match what you expect, use the access-management KB or contact cloud-services@cio.wisc.edu for help.

Complete and Track the Attestation

  1. Select Validate Contacts and Access. Cloud Account Database resolves every required contact in Microsoft Entra and refreshes the synchronized access list.
  2. Review the refreshed results. Confirm that each contact shows Validated and that the access table is correct. A successful check changes the review status to Ready to submit.
  3. Select the confirmation checkbox. Confirm that the account is still in use and that you reviewed its contacts and current access.
  4. Select Complete Attestation once. The button is available only after successful validation and acknowledgment.
  5. Confirm completion. The account page displays Quarterly account attestation completed. The attestation panel is then hidden, and the account is removed from your current-quarter attestation TODO list.

Troubleshooting

Troubleshooting Overview
Problem What to do
I am an Owner, but the attestation controls are not available If you have read-all access, use Switch To My Accounts in the Access View panel, then reopen the account.
A contact does not validate Use an @wisc.edu email address that resolves uniquely in Microsoft Entra. For Security, separate multiple @wisc.edu email addresses with commas and make sure every address resolves.
Validate Contacts and Access is unavailable Add or correct every yellow or red contact card first, then return to Step 4.
Complete Attestation is unavailable Select Validate Contacts and Access, review the refreshed results, and select the confirmation checkbox.
The access list is incorrect Do not complete the attestation. Follow the access-management KB, allow up to 24 hours for synchronization, and validate again.
Contacts, access, or the quarter changed Review the current information and select Validate Contacts and Access again before submitting.
The attestation could not be saved The account remains due and no partial attestation is recorded. Try again or contact cloud-services@cio.wisc.edu.

If you have any questions, feedback or ideas please Contact Us

Commonly Referenced Docs:

UW Madison Public Cloud Team Events
Online Learning Classes for Cloud Vendors
What Data Elements are allowed in the Public Cloud



Keywords:
Cloud Account Attestation Cloud Account Database 
Doc ID:
163434
Owned by:
Brandon E. in Public Cloud
Created:
2026-08-19
Updated:
2026-09-28
Sites:
Public Cloud