Skip to the card

Card 969 of 10002026-08-24 issue

Observed arrival · 2026-08-24

WhyAllowed Explains What an AWS Policy Actually Allows

whyallowed.com Observed source
Editorial interest 84/100 Selection signal · not a rating of the site

A browser-based analyzer that traces effective permissions across AWS IAM, resource policies, SCPs, permissions boundaries, trust policies, KMS keys, and CloudTrail data.

Landing page captured for the 2026-08-24 issue.

Field notes

The interface separates identity-based policies, resource policies, SCPs, permissions boundaries, trust policies, KMS keys, and CloudTrail input before combining their effects. It also accepts contextual account and principal details, plus S3 encryption-key information, rather than treating a policy document in isolation. Example buttons focus on recognizable failure modes such as public S3, GitHub OIDC escalation, SSE-KMS denial, and oversized CloudTrail roles. The page says analysis is performed locally and pasted material disappears when the tab closes.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

LoginAccess appeared gated
PrettyNotable craft visible
ProPolished or operationally mature
NicheUnusually specific use
HumanPersonal, local, civic, or handmade

One card from the complete issue

The Map Rejects the Nearest Shelter

220,141 arrived 1,000 judged 1000 catalogued Enter the complete issue
whyallowed.com

Landing page observed 2026-08-24. The live site may have changed.