Access Your AWS Sandbox Account

How to request and access a temporary AWS sandbox account via the Elite Academy Innovation Sandbox portal.

What is the AWS Sandbox?

The Elite Academy AWS Sandbox is powered by Innovation Sandbox on AWS (ISB) — an AWS Solution that provides managed, temporary AWS accounts. You get a real AWS account with budget limits and a time-based lease. When your lease expires, the account is automatically cleaned up.

🔑

SSO Login

Access via IAM Identity Center — no static keys needed

⏱️

Time-Limited

Account auto-expires after configured duration

💰

Budget Controls

Spend limits enforced with alerts

🔄

Auto Cleanup

All resources removed when lease ends

🛡️

Guardrails

SCPs prevent risky or expensive actions

🌏

Region: ap-southeast-1

Singapore region for low latency

Prerequisites

1 Open the Sandbox Portal

Go to the Innovation Sandbox portal:

https://aws-sandbox.eliteacademy.id

Sign in with your IAM Identity Center credentials (same email and password as Kiro login).

The login page shows the IAM Identity Center sign-in form. Enter your registered email and password.

2 Check for Assigned Leases

Your administrator may have already assigned a lease to you. After logging in, check the dashboard:

  1. Look for an "Active Leases" or "My Leases" section on the dashboard
  2. If you see an active lease with status "Active", you already have access — skip to Step 4
  3. If no lease is assigned, proceed to Step 3 to request one
Assigned leases are pre-configured by your administrator with the correct budget, duration, and permissions for your program. You don't need to do anything — just click "Access Account" to start using it.

Lease Status Meanings

StatusMeaningAction
ActiveAccount is ready to useClick "Access Account"
PendingWaiting for admin approvalWait for notification
FrozenBudget or time limit reached — read-onlyContact admin for extension
ExpiredLease ended, account being cleaned upRequest a new lease

3 Request a New Lease (If Needed)

If you don't have an assigned lease, request one:

  1. Click "Request Lease" or "New Lease"
  2. Select a lease template (your admin may have pre-configured options like "Bedrock Lab" or "General Sandbox")
  3. Review the budget limit and duration
  4. Accept the terms of use
  5. Click "Submit"
If your lease requires approval, you'll need to wait for an administrator to approve it. You'll receive a notification when it's ready.

4 Access Your AWS Account

Once your lease is approved and active:

Option A: AWS Console (Browser)

  1. In the sandbox portal, find your active lease
  2. Click "Access Account"
  3. This opens the AWS Console via SSO — you're logged in automatically

Option B: CLI Credentials (Programmatic Access)

  1. In the sandbox portal, click your active lease
  2. Look for "CLI Credentials" or "Programmatic Access"
  3. Copy the three values:
export AWS_ACCESS_KEY_ID="ASIA..."
export AWS_SECRET_ACCESS_KEY="..."
export AWS_SESSION_TOKEN="..."
These credentials are temporary. They expire when your lease ends or when the SSO session times out. If you get ExpiredTokenException, get fresh credentials from the portal.

Option C: AWS SSO Portal (Direct)

You can also access your sandbox account directly via the SSO portal:

https://eliteacademy.awsapps.com/start
  1. Sign in with your email and password
  2. You'll see your assigned AWS account(s)
  3. Click the account → choose "Management console" or "Command line or programmatic access"

5 Verify Your Access

Once in the AWS Console:

  1. Check the region in the top right — it should say Singapore (ap-southeast-1)
  2. Try opening a service like S3 or Lambda to confirm access works
  3. If you need Bedrock, go to Amazon Bedrock → Model access and check which models are enabled
If Bedrock models aren't enabled, ask your administrator — they may need to enable model access via a blueprint or SCP update.

What You Can Do in the Sandbox

AllowedRestricted
Create Lambda functionsCreate IAM users (use existing roles)
Create S3 bucketsModify organization settings
Use Amazon Bedrock (if enabled)Launch expensive instances (p4d, etc.)
Create API Gateway APIsCreate VPN/Direct Connect
Deploy CloudFormation stacksExceed budget limit
Use DynamoDB, SQS, SNSAccess other accounts

Monitor Your Lease

In the sandbox portal, your lease shows:

When your budget reaches the threshold or your lease time expires, your account will be frozen. You'll lose access and all resources will be cleaned up automatically.

Using Sandbox Credentials with GitHub Actions

If you're deploying via GitHub Actions (e.g., the PartyRock tutorial), add these as GitHub secrets:

Secret NameValue
AWS_ACCESS_KEY_IDFrom CLI credentials (starts with ASIA)
AWS_SECRET_ACCESS_KEYFrom CLI credentials
AWS_SESSION_TOKENFrom CLI credentials (very long string)
SAM_DEPLOY_BUCKETCreate one in S3, or use a pre-existing bucket
Sandbox credentials expire. When you get a new session, you must update all 3 credential secrets in GitHub with fresh values.

Troubleshooting

IssueSolution
"Access Denied" in consoleYour lease may have expired or been frozen. Check the sandbox portal.
ExpiredTokenExceptionGet fresh CLI credentials from the sandbox portal.
Can't create IAM rolesSCPs restrict this. Use the pre-existing execution role provided by the sandbox.
Bedrock models not availableAsk your admin to enable model access for the sandbox OU.
"Budget exceeded"Your spend hit the limit. Ask admin to increase or wait for a new lease.
Account shows "Frozen"Budget or time limit reached. You can view but not modify resources.
Can't access certain regionsSCPs may restrict regions. Use ap-southeast-1 (Singapore).

Quick Reference

SettingValue
Sandbox Portalaws-sandbox.eliteacademy.id
SSO Portaleliteacademy.awsapps.com/start
Regionap-southeast-1 (Singapore)
Your usernameYour registered email address
Credentials typeTemporary (session token required)

Need Help?

TypeContact
Lease approval / budget increaseContact your program administrator
Password resetAsk admin to resend from IAM Identity Center
Technical issuesContact your program's technical coach