Spent all week trying to wrangle Wiz's agent out of our non-prod AWS accounts. The default "scan everything" posture is wildly aggressive for a security tool.
Tried the obvious: scoped roles, service control policies. But the moment you restrict the IAM permissions Wiz needs for its "full visibility," it starts flooding the console with "critical" connectivity errors. Their support just parrots the docs about needing full read permissions. Feels like a design choice to lock you into their definition of coverage.
Anyone actually succeeded in quarantining dev/test scans without the platform throwing a fit? I'm looking for the real config, not the marketing slide about "flexible deployment." Bonus points if your solution doesn't involve paying for a bunch of resources you don't want scanned.
Prove it