IAM policy explainer
Paste an AWS IAM policy and read what it allows in plain English, statement by statement, with the risky parts flagged.
It runs entirely in your browser. The policy you paste is never sent to Cloud GUI or anyone else, and nothing is saved.
An identity policy, a bucket or key policy, or a role's trust policy. What aws iam get-policy-version, aws iam get-role or aws s3api get-bucket-policy prints works too.
How to read an IAM policy
A policy is a list of statements. Each statement says:
- Effect:
AlloworDeny. - Action: which AWS API calls, written
service:Action, likes3:GetObject.*is a wildcard. NotAction means "everything except these". - Resource: which things, by ARN, like
arn:aws:s3:::my-bucket/*.*means everything, or, in a bucket or key policy, that bucket or key. - Principal: who. Only policies attached to a resource, and roles' trust policies, have one. A policy attached to a user or role applies to that user or role.
- Condition: only when, such as from certain IP addresses, with MFA, or with a particular external ID.
How AWS decides
- Anything that isn't allowed is denied.
- A
Denybeats anyAllow, wherever it is. - Across accounts, both sides have to allow it: the caller's own policies, and the resource's policy (or the role's trust policy).
- Service control policies from AWS Organizations, and permissions boundaries, can only take permissions away. They never add any.
What it flags
- High risk: full admin access; every action in IAM, S3 or another sensitive service on everything;
iam:PassRoleon any role; actions that change IAM permissions;NotActionwith Allow; public access; trust policies that any AWS account or any GitHub repository could use. - Worth checking: reading data (files, secrets, items) everywhere; changing who has access to things; trusting a whole account without an external ID; conditions that are all that keeps something private.
- Notes and problems: classic mistakes like
s3:GetObjecton a bucket ARN, typos AWS would reject, and a missingVersion.
It explains; it doesn't decide. A flagged pattern can be right for your situation, and a clean result doesn't prove a policy is safe: it can't see your other policies, your organization's rules or what your resources hold. To check a whole account, AWS's IAM Access Analyzer is the tool.
Related guides
- What "AccessDenied when calling the AssumeRole operation" means, and how to fix it
- How to see a Lambda function's environment variable names without showing their values
- All guides
Cloud GUI's own permissions are public, too. Here's exactly what its read-only role can and can't do, and you can paste its trust policy above (it's one of the samples).