Can I? — AWS permission evaluator

Toggle the scenario; the diagram and verdict update live. Press Run request to send a request through the gates and watch where it stops. Nested boxes are policy scopes — SCP/RCP wrap the account, the boundary and identity/resource policies wrap the principal and resource.

Deciding rule
Fix