Observed arrival · 2026-08-24
WhyAllowed Explains What an AWS Policy Actually Allows
A browser-based analyzer that traces effective permissions across AWS IAM, resource policies, SCPs, permissions boundaries, trust policies, KMS keys, and CloudTrail data.
Field notes
The interface separates identity-based policies, resource policies, SCPs, permissions boundaries, trust policies, KMS keys, and CloudTrail input before combining their effects. It also accepts contextual account and principal details, plus S3 encryption-key information, rather than treating a policy document in isolation. Example buttons focus on recognizable failure modes such as public S3, GitHub OIDC escalation, SSE-KMS denial, and oversized CloudTrail roles. The page says analysis is performed locally and pasted material disappears when the tab closes.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue