AIToday

Deepgram integrates AWS IAM temporary delegation for SageMaker support access

Amazon AI Blog3h agoSend on LINE
Deepgram integrates AWS IAM temporary delegation for SageMaker support access

Key takeaway

Deepgram has integrated AWS IAM temporary delegation into its support ticketing system for customers running speech AI models on Amazon SageMaker AI. This allows Deepgram engineers to request scoped, time-limited access to customer endpoints and logs with customer approval from their own IAM console, reducing investigation time from days to minutes and eliminating the need for long-lived cross-account IAM roles. Every delegated action is automatically logged in the customer's AWS CloudTrail with Deepgram's account ID for audit compliance.

Summaries like this, in your inbox every morning.

Sign up free →

3 Key Points

  • What happened

    Deepgram has integrated IAM temporary delegation, a new AWS IAM capability, into its support workflow for customers running Deepgram speech AI models on Amazon SageMaker AI. The integration allows Deepgram engineers to request time-limited, scoped access to customer endpoints and logs directly from the support ticketing system, with customers approving requests in their own IAM console.

  • Why it matters

    This replaces the previous model of long-lived cross-account IAM roles, which required recurring provisioning and audit conversations. Deepgram has reduced the time for initial investigation on a SageMaker AI support ticket from days to minutes, since customers can now approve access in their IAM console rather than scheduling screen-shares. Every delegated API call is tagged in AWS CloudTrail with Deepgram's partner account ID for full auditability.

  • What to watch

    Credentials issued through the integration expire automatically after twelve hours, and customers can revoke access at any time before expiration. The integration requires an active Deepgram support contract, an enabled AWS CloudTrail trail in the region where the SageMaker AI endpoint runs, and AWS infrastructure charges for SageMaker AI endpoint hosting, Amazon CloudWatch logs, AWS CloudTrail, and networking (Deepgram offers a 14-day trial at no additional cost for its models, but AWS infrastructure costs apply from the start of deployment).

In Depth

Amazon SageMaker AI provides a managed control plane for deploying Deepgram speech models inside a customer's own AWS account. The platform offers AWS Marketplace listings for Deepgram's Nova, Flux, and Aura-2 models (covering both speech-to-text and text-to-speech), validated reference architectures for VPC isolation and auto-scaling, and Terraform modules that platform teams can integrate into their existing infrastructure. This approach closes the gap between self-hosting—which enterprises choose for data residency, network isolation, and regulatory compliance—and the operational maturity of a managed cloud service.

Production deployments inevitably require support. A model returns unexpected results, an endpoint autoscales slower than expected, or GPU utilization looks off. The engineer best positioned to diagnose the issue is on the Deepgram team, but they have no access to the customer's Amazon VPC. The traditional options all had drawbacks: long-lived cross-account IAM roles required customers to provision, audit, and revoke them repeatedly; shared screens and copy-pasted logs were slow and error-prone, and unsuitable for regulated environments; asking customers to run commands on Deepgram's behalf did not scale for iterative troubleshooting.

IAM temporary delegation, a new AWS IAM capability, solves this by allowing partners to request scoped, time-limited, customer-approved access to specific resources with no long-lived credentials, no cross-account roles, and no shared secrets. The workflow is built directly into Deepgram's support ticketing system. A Deepgram engineer runs the /delegate_access command in the customer support ticket, the customer replies with their SageMaker AI endpoint ARN, and the integration calls iam:CreateDelegationRequest with a pre-registered DeepgramSageMakerReadOnlyTroubleshooting permission template. The customer opens a deep link to their IAM console, reviews the fully resolved permissions (with every resource ARN spelled out and no wildcards), and chooses Approve to grant read-only access to exactly one CloudWatch log group and one DescribeEndpoint resource. AWS then issues short-lived STS credentials scoped to the template and bounded by a twelve-hour SessionDuration. The credentials are posted to the ticket's internal discussion, and every API call made with them is tagged in the customer's AWS CloudTrail with Deepgram's partner account ID. The customer can revoke access at any time before expiration.

The integration has reduced the time for initial investigation on a SageMaker AI support ticket from days—previously requiring a screen-share scheduled across both calendars—to minutes. For Deepgram's security-conscious enterprise buyers, it replaces a recurring IAM role provisioning conversation with a no-standing-access posture that is strictly stronger than the alternative. Customers running this integration incur AWS charges for SageMaker AI endpoint hosting (including GPU instances), Amazon CloudWatch logs, AWS CloudTrail, and associated networking resources. Deepgram offers a 14-day trial at no additional cost for its models, but AWS infrastructure costs apply from the start of deployment.

Context & Analysis

Deepgram's self-hosted deployment on Amazon SageMaker AI addresses a core enterprise requirement: running speech AI models within a customer's own AWS account for data residency, network isolation, and regulatory compliance—without sacrificing the operational maturity of a managed cloud service. The body describes how Deepgram has invested across three dimensions: AWS Marketplace listings with one-click subscription, validated reference architectures covering VPC isolation and auto-scaling, and Terraform modules that platform teams can layer onto existing infrastructure.

The support access problem solved by IAM temporary delegation reflects a tension at the heart of self-hosted deployments. When a model misbehaves or an endpoint autoscales unexpectedly, the engineer best positioned to diagnose the issue is often on the Deepgram side—but that engineer has no access to the customer's VPC. The traditional remedies all carried operational costs: long-lived cross-account IAM roles required recurring audit and revocation conversations; screen-shares and copy-pasted logs were slow and audit-unfriendly; asking customers to run commands on behalf of Deepgram did not scale. IAM temporary delegation addresses all three drawbacks by issuing scoped, time-limited credentials directly in the customer's IAM console, with every action tagged for audit and zero standing trust between accounts.

FAQ

How long does delegated access last?
Credentials expire automatically after twelve hours. Customers can revoke access at any time before expiration by choosing Revoke on the delegation request in the IAM console.
What permissions does a Deepgram engineer get through the integration?
The integration grants read-only access to exactly one Amazon CloudWatch log group and one DescribeEndpoint resource for the customer's specified SageMaker AI endpoint. Every resource ARN is fully resolved with no wildcards, and the customer can review the complete permissions before approving.
What Deepgram models are available on SageMaker AI?
Deepgram offers AWS Marketplace listings for Nova, Flux, and Aura-2, which cover speech-to-text (STT) and text-to-speech (TTS) models.

Get the latest Audio & Speech news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Discussion

No comments yet. Be the first to share your thoughts!

Log in to join the discussion

Related Articles

Stay ahead with AI news

Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.

Get Started Free

Free · takes 30 seconds · unsubscribe anytime