IAM · Resource policy · SCP · Permissions boundary

WhyAllowed

Paste AWS policy JSON. See who can actually reach what, why they can reach it, and what breaks if that identity is stolen.

Runs entirely in this browser

Identity-based policy attached to a user, group or role. No Principal block.

Context

optional

Nothing analysed yet

Paste at least one policy on the left, then run the analysis. Paste both an IAM policy and a resource policy (S3, SQS, SNS, Secrets Manager, Lambda or ECR) to see the combined, final answer for a principal.

1. Paste policy JSON 2. Analyse 3. Read the verdict, not the JSON