What problem does it solve?
It turns a manual IAM security review into a single structured investigation, helping you find who has effective admin access, how roles and accounts trust each other, and what Identity Center permission sets actually grant.
Core Features & Use Cases
- Admin-equivalent discovery: Finds direct admins, indirect admins through assume-role paths, and group-based admin access.
- Trust-chain analysis: Maps cross-account trust relationships, multi-hop role chaining, and identity provider to AWS role mappings.
- PermissionSet review: Expands Identity Center permission sets into the roles and policies they provision, including admin-equivalent grants.
- Use case: Use it during an access review, incident response, or privilege escalation investigation to produce a clear IAM risk summary from the SubImage graph.
Quick Start
Ask the assistant to audit IAM privilege for the target AWS account or role and return the direct admins, trust chains, PermissionSet grants, and risk summary.