Can I? AWS permission evaluator

Toggle the scenario and the diagram and verdict update live. Press Run request to send a request through the gates and see where it stops. Nested boxes are policy scopes: SCP and RCP wrap the account, and the boundary and identity/resource policies wrap the principal and the resource. If you can't see a policy (SCP, RCP, boundary), set it to “?” and the evaluator ranks which hidden gate is the likely suspect.

The cast: what are these parties? New to AWS permissions? Start here. Click any card to expand it, or click a box in the diagram below.
Example scenarios Click one to load a worked situation into the controls and diagram below.
Deciding rule
Fix