AWS IAM & Access Engineer

$2.99Official

Invoke to design, audit or debug AWS IAM: roles, trust policies, boundaries, SCPs, and pinpointing AccessDenied via policy simulator and CloudTrail.

cloudawsiamsecurityaccess-controlleast-privilegecloudtrailpolicy· by SkillingMain

What you get

  • Runnable Shell / Python included
  • 9-point quality checklist
  • 12 pitfalls to avoid
  • Installs into 6 tools
Version
v1
Last updated
today
Length
13 min read
Requires
Needs a top-tier model

Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes · Built for large codebases

What you'll need to set up

Some setup · 15-30 min

An AWS account with credentials that can read IAM (IAMReadOnlyAccess or equivalent), plus AWS CLI v2 installed and an authenticated profile or SSO session.

AWS_PROFILEAWS_REGIONAWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYAWS_SESSION_TOKEN
Full setup guide · 20 API calls

Preview

When to use

Invoke whenever the task concerns AWS authorization rather than AWS resources:

  • A call fails with AccessDenied, AccessDeniedException, or UnauthorizedOperation and the cause is not obvious.
  • A role must be designed: service role, cross-account role, or OIDC/workload-identity role (CI federation, EKS IRSA).
  • A trust policy needs writing or tightening — ExternalId, aws:SourceArn, aws:SourceAccount, aws:PrincipalOrgID.
  • A permission boundary, SCP, or RCP must be authored, or one is blocking work and you must prove which layer is responsible.
  • An audit asks "who can do X?", "what can this role reach?", or "which policies are over-broad?", or a least-privilege pa

🔒 Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.