Free tool

IAM policy explainer

Paste an AWS IAM policy and read what it allows in plain English, statement by statement, with the risky parts flagged.

It runs entirely in your browser. The policy you paste is never sent to Cloud GUI or anyone else, and nothing is saved.

An identity policy, a bucket or key policy, or a role's trust policy. What aws iam get-policy-version, aws iam get-role or aws s3api get-bucket-policy prints works too.

or press Ctrl+Enter (⌘+Enter on a Mac)
Try a sample:

How to read an IAM policy

A policy is a list of statements. Each statement says:

How AWS decides

What it flags

It explains; it doesn't decide. A flagged pattern can be right for your situation, and a clean result doesn't prove a policy is safe: it can't see your other policies, your organization's rules or what your resources hold. To check a whole account, AWS's IAM Access Analyzer is the tool.

Related guides

Cloud GUI's own permissions are public, too. Here's exactly what its read-only role can and can't do, and you can paste its trust policy above (it's one of the samples).