Status: Live. Connected Environments is the one place environments are added, authorized, verified, repaired and retired. It is a product layer over one canonical environment identity — the same cluster reported by Fleet and by Edge is one environment, never two.

Two EKS environments, both Ready on Fleet + Edge evidence, both execution-ready on the Cloud Executor, both in Advise — and each environment's latest Permit, including one revoked by a human.
Flows
- AWS / EKS (Fleet, recommended). Connect the account once in AWS Account Center → Environments → Add environment → AWS / EKS discovers every EKS cluster in the authorized regions → select → Authorize selected registers them → apply the generated read-only grant with your own credentials → Verify until the first evidence arrives (typically within a minute). Discovery never enrolls anything.
- Kubernetes (Edge). Add environment → Kubernetes: name the environment → Authorize enrolls it → apply the generated install (the environment’s credential is embedded; nothing is typed) → Verify. See Fleet, Edge and the Executor.
- Edge as an extension. For an environment Fleet already reads, add Edge to the same card; the canonical merge keeps one environment with provenance Fleet + Edge.
Evidence, judgment readiness and execution are three different things
- Evidence is what ChangeGuard knows — read-only, from Fleet, Edge or both.
- Judgment readiness says whether a judgment against this environment would be fully informed right now. Evidence past the 15-minute bound is treated as absent by a judgment, never as current.
- Execution is whether ChangeGuard can act here at all — a separately enabled, separately identified path proven by Verify execution access — and the latest Permit shows what, if anything, is currently authorized. Read authority never implies write authority; nothing executes without a Permit.