AWS Permission Review
A CLI and pull-request workflow for explaining changes to IAM policies, with evidence and an explicit analysis scope.
Explore the project →I build developer tools and reliable backend systems, and share the decisions behind them through code, articles, and walkthroughs.
Policy: report-worker + Action entry: s3:DeleteObject ~ Resource entry changed to "*" Review the intended access. Scope: supplied policy documents. Effective access: not evaluated.
Starting with permission reviews for small AWS-based software teams.
A CLI and pull-request workflow for explaining changes to IAM policies, with evidence and an explicit analysis scope.
Explore the project →A structural change is useful evidence. Understanding effective access requires a wider view.
Read the note →Short demonstrations covering implementation decisions, tests, and what each tool can actually establish.
See the video plan →Small, reproducible examples and a focused first release. Add complexity when the workflow needs it.
Correctness, failure handling, and supported scope belong alongside the implementation.
Publish the reasoning, limitations, and changes made after feedback. Let people assess the work.
Tell me what your team is trying to review, automate, or make more reliable. We can discuss a focused implementation and a clear handover.
Discuss your workflow →