Evaluate the request, not the policy name

An asset reader may have a managed policy named read-only, but names are not an authorization decision. The evaluator must compare the action and resource to the actual statements, including inherited group permissions and restrictions.

Action names are matched without case sensitivity. Resource names and relevant string condition values can be case sensitive. A resource scoped to an object named Report does not automatically grant access to report. Try that distinction in the model.

An allow is necessary but may not be sufficient

With no applicable allow, the result is an implicit deny. With a matching explicit deny, the deny wins. A permissions boundary constrains what identity permissions can grant; it does not independently grant access.

The model covers same-account identity policies and a boundary, plus a limited resource-policy example. It does not simulate a complete Organizations hierarchy, cross-account trust or every condition operator. Unsupported statements produce a visible unsupported result.

Repair the narrow cause

Start with an allow and a matching deny. Predict the outcome, run evaluation, then remove the deny while keeping the allow. Next add a boundary that excludes the operation. The result remains denied, but for a different reason.

In a real account, confirm the caller with STS GetCallerIdentity, identify the protected operation, and locate the responsible restriction. That STS operation itself requires no permission, so it is not a good example of an ordinary protected read.

Least privilege is an effective permission test

Placing a read-only policy on one group does not make a user read-only if a different group grants administrator access. A lab should bind its checks to the same user and test allowed reads and denied writes.

Use groups to manage permissions for this practice user exercise. For production workloads, prefer an appropriate role and temporary credentials. The console identity selector below is simulated authorization, not a site login.

SimAWS · ShahriarLabs

Predict it. Test it. Change one thing.

Local educational model. No account or cloud charges. Nothing is deployed to AWS.

Asset reader request

s3:GetObject on arn:aws:s3:::lesson-assets/Report.txt

{
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::lesson-assets/Report.txt"
    }
  ]
}

Selected same-account identity-policy behavior. This is not a complete AWS policy simulator.

sim.shahriarlabs.com · Free to explore

Sources and scope

Reviewed against these official references. The model’s supported scope appears alongside its controls.

How we review explanations