← All Tools
IAM Policy Analyzer
Your policy said *:*. That’s an all-you-can-eat buffet for attackers. Paste an AWS, Azure or GCP policy and get a grade, the findings in plain English, and a least-privilege starting point.
🔒 Nothing you paste here is sent anywhere. The analysis runs in this tab; there is no endpoint behind this page — check your browser’s network tab. Nothing is written to browser storage: an IAM policy reveals your account structure and it stays in memory only.
Load example:
–
Findings
Statements as read
| Ref | Effect | Actions | Resources / members | Condition |
|---|
Least-privilege starting point advisory — not exhaustive
Wildcards are narrowed to a known read set for the services the statement touches; placeholders mark what only you can fill in. Add the write actions the workload can prove it needs (CloudTrail, IAM Access Analyzer), keep every Deny, and re-run.
⚠ Advisory only. The rules (2026-09-19.1, 22 checks) catch the common over-grants, not every escalation path; a clean grade is not an authorisation review. Tools are provided for educational and authorized use only.