One archive control plane. Many teams and AWS boundaries.
Give platform teams consistent governance while letting each product or data group keep its own buckets, workers, roles, and operating context.
Scope compute to the teams it serves
A worker belongs to a user and can be assigned to several teams. On every claim, Data Convoy checks that the owner still manages the target team, so role revocation immediately shrinks the worker’s reach.
Keep AWS access in AWS
Run workers against roles in your accounts. Server-side S3 copies avoid download-and-upload data paths, while the control plane coordinates job state and protected metadata.
Operate across accounts without flattening ownership
Teams hold their own production, archive, and backup configuration. Site administrators can manage the service without turning every operator into an all-powerful account.
Your buckets. Your workers. Your control.