Security, Identity, and Compliance
IAM Access Analyzer
IAM Access Analyzer identifies external or unused access and validates IAM policies using automated reasoning and access activity. It helps GenAI teams tighten data, model, key, and role permissions before deployment.
Key points
- External-access findings evaluate supported resource policies against a zone of trust
- Unused-access analysis highlights stale permissions from observed activity
- Policy validation reports security warnings, errors, and best-practice suggestions
When to use it
- Detect an S3 corpus policy that trusts another account
- Refine a broad agent execution role from observed usage
Exam tips
- Choose Access Analyzer for policy analysis and CloudTrail for the underlying API history
- A lack of findings is not proof of application-level tenant isolation