Cloud IAM

In a cloud estate of any size, nobody can tell what an account is actually able to do by reading its permissions.

Access comes from layers that combine: the policy on the identity, the policy on the resource, the role it can assume, the permissions that role holds, inherited settings from the organisation. The effective answer is the result of all of them interacting, and it routinely surprises the people who wrote them. This is why tooling that answers "what can this actually reach" is worth more than another review of the documents.

Checked against the primary source.

More on Cloud security