S3 Credentials Generation for Conversation Ingestion
Last updated: August 19, 2026
This article explains how to configure a client's AWS environment for Level AI to securely copy files from your Amazon S3 bucket to our Google Cloud Storage (GCS) bucket using role-to-role (cross-account) assumption. The integration runs on a schedule, picks up files from a pending folder, copies them to Level AI’s storage, and then moves them to a processed folder in your bucket.
Overview
What it does: Level AI’s system connects to clients S3 bucket, lists files under a pending path client specifies, copies those files to LevelAI’s GCS bucket, and then moves them in client’s bucket from pending to processed folders.
Security: Access uses role-to-role assumption. Level AI first assumes a role in our AWS account, then uses that to assume a role in the client's AWS account. No long-lived access keys are stored. Client’s IAM role’s trust policy allows only Level AI’s AWS role to assume it.
Prerequisites
An AWS account with permissions to create IAM roles and manage S3.
An S3 bucket (existing or new) in the region where clients want to hold the files.
A clear decision on where in the client’s bucket the pending (and processed) folders will live (e.g. top-level pending/ or under a prefix like exports/pending/).
Step 1: S3 Bucket and Folder Structure
3.1 Create or designate an S3 bucket
Use an existing bucket or create a new one in your chosen AWS region.
Note the bucket name and region; These details would need to be shared with LevelAI.
3.2 Define the folder layout
The integration expects:
A pending folder location: where client’s place files to be transferred.
A processed folder location: where we can move files after a successful copy to LevelAI (same level as pending).
Sample Folder Structure (top-level) :
Pending path: pending
Processed path: processed
Example object keys: pending/file1.csv, processed/file1.csv
3.3 Place files for transfer
Upload or write files into the pending path (and subfolders if you use them). The integration discovers files recursively under the pending path.
Do not rely on date-based filtering; the integration processes whatever is under the pending path at run time.
Step 2: IAM Role for Level AI Access
Create an IAM role in the client's AWS account that Level AI will assume via role-to-role.
4.1 Create the role
In the AWS Console, visit IAM → Roles → Create role.
Trusted entity type: Choose Custom trust policy (we will define the trust in Step 3).
Role name: e.g. LevelAI-S3-FileTransfer-Role (or any other name according to standards)
Description: e.g. “Allows Level AI to read from pending and move to processed in S3 for GCS transfer.”
4.2 Attach a permissions policy to the role
The role needs permissions to:
List the bucket (and list/read under the pending or processed prefix).
Read (GetObject) objects under the pending path.
Write (PutObject) and delete (DeleteObject) under the processed path (for the move operation).
Optionally list/read under the processed path if you need it.
Example policy (replace YOUR-BUCKET-NAME and optional prefix):
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ListBucket",
"Effect": "Allow",
"Action": [
"s3:ListBucket",
"s3:GetBucketLocation"
],
"Resource": "arn:aws:s3:::YOUR-BUCKET-NAME"
},
{
"Sid": "ReadPendingAndWriteProcessed",
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject",
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::YOUR-BUCKET-NAME/*"
]
}
]
}
Client’s can restrict Resource to specific prefixes (e.g. arn:aws:s3:::YOUR-BUCKET-NAME/tenant-name/*). After creating the role, Please store the ARN (e.g. arn:aws:iam::123456789012:role/LevelAI-S3-FileTransfer-Role).
5. Step 3: Configure Role-to-Role Trust
Level AI uses role-to-role (cross-account) assumption: our AWS role assumes your role. You must allow Level AI’s role as a trusted principal.
5.1 Get Level AI’s role ARN
Level AI TAM/Support/IM will provide our Level AI Role ARN (e.g. arn:aws:iam::826093755571:role/level-ai-gcp-oidc-assume-role). Request this from your Level AI contact before completing the trust policy.
5.2 Set the trust policy on your role
Edit the trust policy of the role you created in Step 2 so that the principal is Level AI’s role ARN and the action is sts:AssumeRole.
Example trust policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::LEVEL-AI-ACCOUNT-ID:role/LEVEL-AI-ROLE-NAME"
},
"Action": "sts:AssumeRole"
}
]
}
Replace LEVEL-AI-ACCOUNT-ID and LEVEL-AI-ROLE-NAME with the values from the Level AI Role ARN provided to you. Only this principal will be able to assume your role; no access keys or secrets are required.
6. Information to Share with Level AI
Please provide the following in a secure channel:
Key | Description | Example |
Customer Role ARN | The ARN of the IAM role Level AI will assume (created in Step 2) | arn:aws:iam::545009865583:role/LevelAI-S3-Access-Role |
S3 Bucket Name | Name of the S3 bucket | my-company-data-bucket |
AWS Region | Region where the bucket is located | eu-north-1 or us-east-1 |
Pending Folder Path | Full path/prefix in the bucket where pending files live | pending or folder1/folder2/pending |
Level AI will provide our Level AI Role ARN to clients to use in the role's trust policy (Step 3). No access keys or secrets are required.
Ongoing Usage and Support
Adding files: Place new files under the agreed pending path. The integration will pick them up on its next run.
Processed files: After a successful copy, files are moved within the client's bucket from the pending path to the corresponding processed path. Level AI retains copies in our GCS bucket per our data processing terms.
Changes: If clients change bucket name, region, path, or role ARN, share the updated details with Level AI so we can update the integration.
Issues: For connection errors, permission errors, or missing files, contact your Level AI representative with the approximate time of the run and (if applicable) example object keys.