How to request and access a temporary AWS sandbox account via the Elite Academy Innovation Sandbox portal.
The Elite Academy AWS Sandbox is powered by Innovation Sandbox on AWS (ISB) — an AWS Solution that provides managed, temporary AWS accounts. You get a real AWS account with budget limits and a time-based lease. When your lease expires, the account is automatically cleaned up.
Access via IAM Identity Center — no static keys needed
Account auto-expires after configured duration
Spend limits enforced with alerts
All resources removed when lease ends
SCPs prevent risky or expensive actions
Singapore region for low latency
Go to the Innovation Sandbox portal:
https://aws-sandbox.eliteacademy.id
Sign in with your IAM Identity Center credentials (same email and password as Kiro login).
Your administrator may have already assigned a lease to you. After logging in, check the dashboard:
| Status | Meaning | Action |
|---|---|---|
| Active | Account is ready to use | Click "Access Account" |
| Pending | Waiting for admin approval | Wait for notification |
| Frozen | Budget or time limit reached — read-only | Contact admin for extension |
| Expired | Lease ended, account being cleaned up | Request a new lease |
If you don't have an assigned lease, request one:
Once your lease is approved and active:
export AWS_ACCESS_KEY_ID="ASIA..."
export AWS_SECRET_ACCESS_KEY="..."
export AWS_SESSION_TOKEN="..."
ExpiredTokenException, get fresh credentials from the portal.You can also access your sandbox account directly via the SSO portal:
https://eliteacademy.awsapps.com/start
Once in the AWS Console:
| Allowed | Restricted |
|---|---|
| Create Lambda functions | Create IAM users (use existing roles) |
| Create S3 buckets | Modify organization settings |
| Use Amazon Bedrock (if enabled) | Launch expensive instances (p4d, etc.) |
| Create API Gateway APIs | Create VPN/Direct Connect |
| Deploy CloudFormation stacks | Exceed budget limit |
| Use DynamoDB, SQS, SNS | Access other accounts |
In the sandbox portal, your lease shows:
If you're deploying via GitHub Actions (e.g., the PartyRock tutorial), add these as GitHub secrets:
| Secret Name | Value |
|---|---|
AWS_ACCESS_KEY_ID | From CLI credentials (starts with ASIA) |
AWS_SECRET_ACCESS_KEY | From CLI credentials |
AWS_SESSION_TOKEN | From CLI credentials (very long string) |
SAM_DEPLOY_BUCKET | Create one in S3, or use a pre-existing bucket |
| Issue | Solution |
|---|---|
| "Access Denied" in console | Your lease may have expired or been frozen. Check the sandbox portal. |
ExpiredTokenException | Get fresh CLI credentials from the sandbox portal. |
| Can't create IAM roles | SCPs restrict this. Use the pre-existing execution role provided by the sandbox. |
| Bedrock models not available | Ask your admin to enable model access for the sandbox OU. |
| "Budget exceeded" | Your spend hit the limit. Ask admin to increase or wait for a new lease. |
| Account shows "Frozen" | Budget or time limit reached. You can view but not modify resources. |
| Can't access certain regions | SCPs may restrict regions. Use ap-southeast-1 (Singapore). |
| Setting | Value |
|---|---|
| Sandbox Portal | aws-sandbox.eliteacademy.id |
| SSO Portal | eliteacademy.awsapps.com/start |
| Region | ap-southeast-1 (Singapore) |
| Your username | Your registered email address |
| Credentials type | Temporary (session token required) |
| Type | Contact |
|---|---|
| Lease approval / budget increase | Contact your program administrator |
| Password reset | Ask admin to resend from IAM Identity Center |
| Technical issues | Contact your program's technical coach |