Identity and permission are separate questions

A user or assumed role can be allowed or denied by applicable policy. Choosing a role does not automatically grant broad permissions; attaching AdministratorAccess is not a substitute for identifying required actions.

The practice user-and-group lab teaches inherited permissions in a local sandbox. It is not a recommendation to create long-lived credentials for every person or application in production.

Why temporary credentials matter

An EC2 workload can use an appropriate role instead of a user access key embedded in source or configuration. Temporary credentials reduce the need to store and manually rotate long-lived secrets. They still require suitable trust and permissions.

For people, AWS recommends federation with temporary credentials where appropriate. Choose the organization access model, then grant the least privilege needed for the task.

Evaluate effective permission

Use the policy experiment to test a read, a write and a matching explicit deny. Read-only group membership does not cancel another group granting writes. A boundary constrains grants rather than creating them.

The console identity selector changes the simulated caller. It never logs you into AWS and does not create a ShahriarLabs account. The local engine models selected identity policy behavior, not credential issuance or a complete STS role session.

Use a scenario to defend your choice

For the practice asset reader, explain which objects it needs, which operations it performs and how it receives credentials. For an administrator, explain the federation or access path and stronger access needs.

The useful answer includes both credential lifecycle and authorization scope. A role can still be overprivileged, and a correctly scoped policy can still be paired with unsafe credential storage.

SimAWS · ShahriarLabs

Predict it. Test it. Change one thing.

Local educational model. No account or cloud charges. Nothing is deployed to AWS.

Asset reader request

s3:GetObject on arn:aws:s3:::lesson-assets/Report.txt

{
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::lesson-assets/Report.txt"
    }
  ]
}

Selected same-account identity-policy behavior. This is not a complete AWS policy simulator.

sim.shahriarlabs.com · Free to explore

Sources and scope

Reviewed against these official references. The model’s supported scope appears alongside its controls.

How we review explanations