IAM Policy and Access Audit

This workflow runs a report to identify IAM users and roles with excessive permissions. If findings are present, it moves to an approval stage and then remediates the excessive permissions via a blueprint; if no findings, the workflow ends with no action.

1. Run IAM Excessive Permissions Report

  • Generate a report that identifies IAM users and roles with excessive permissions.

2. Evaluate Report Findings

  • If no IAM entities have excessive permissions, return 'none'; if findings exist, return 'approval'.

3. Approve IAM Remediation Actions

  • Request approval to remediate excessive permissions for IAM users and roles.

4. Remediate Excessive IAM Permissions

  • Apply remedial adjustments based on the report: reduce and tighten permissions for the affected IAM users and roles.
Workflow Ready

IAM Policy and Access Audit

Start
Manual
Run IAM Excessive Permissions Report
Blueprint: report_iam_excess_pe...
Evaluate Report Findings
Approve IAM Remediation Actions
Remediate Excessive IAM Permissions
Blueprint: cloudtask_remediate_...
End (No Action)
End