What problem does it solve? AWS Clean Rooms collaborations fail with opaque permission errors spanning IAM roles, S3 bucket policies, KMS keys, and Lake Formation, and custom ML training or inference jobs often produce no CloudWatch logs. This Skill provides systematic diagnostic procedures that pinpoint the exact root cause instead of trial-and-error permission changes. ## Core Features & Use Cases - Permission Debugging: Traces access denied errors through IAM role policies, S3 bucket policies, KMS key policies, Lake Formation grants, and cross-account trust configurations. - ML Logging Diagnostics: Investigates missing CloudWatch logs for custom model training and inference jobs by checking privacy configurations, ML Configuration roles, and log group existence. - Use Case: A customer reports that their Clean Rooms ML training job completed but no logs appear in CloudWatch. The Skill walks through the Configured Model Algorithm Association privacy configuration, verifies the ML Configuration role has logs:CreateLogGroup and logs:PutLogEvents permissions, and produces a diagnosis with the exact CLI fix. ## Quick Start Diagnose why my Clean Rooms membership is getting an access denied error when running a protected query in region us-east-1.