What problem does it solve? AWS Clean Rooms collaborations often fail with opaque access denied errors or silently missing CloudWatch logs for custom ML training and inference jobs. This Skill provides systematic diagnostic procedures to pinpoint the exact root cause across IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions, and ML Configuration settings. ## Core Features & Use Cases - Permission Debugging: Traces access errors through IAM role policies (inline and managed), S3 bucket policies, KMS key policies, Lake Formation grants, and cross-account trust configurations. - Custom Model Logging Diagnosis: Investigates why CloudWatch logs are not published for trained models or inference jobs by checking privacy configurations, ML Configuration roles, and log group existence. - Use Case: A customer runs a protected query that fails with AccessDenied. The Skill walks through the membership configuration, resolves the configured table to its S3 bucket via Glue, checks the data access role's IAM and Lake Formation permissions, and outputs the exact policy fix with CLI commands. ## Quick Start Diagnose why my Clean Rooms protected query is failing with an access denied error in membership m-123abc in us-east-1.