Security, Identity, and Compliance
IAM Identity Center
IAM Identity Center centrally manages workforce access to AWS accounts and supported applications using users, groups, federation, and permission sets. It gives GenAI administrators short-lived, role-based workforce access without proliferating IAM users.
Key points
- Permission sets provision roles into assigned AWS accounts
- External identity providers can supply workforce users and groups
- Application assignments are distinct from resource-level authorization inside each application
When to use it
- Grant data scientists time-bounded access to a GenAI development account
- Control which employees can administer an enterprise AI application
Exam tips
- Choose Identity Center for workforce access and Cognito for customer-facing application identities
- Keep permission sets job-aligned and use separate production roles for high-impact model or data operations