These pages document intended workflows. They do not start jobs, connect accounts or run hosted automations. Implementation and service access are separate prerequisites.
Watches CloudTrail for over-permissive policy writes, reasons against 90 days of real access, and opens a scoped Terraform PR — verified in the IAM simulator first.
On incident resolution, pulls the Slack war-room and PagerDuty timeline, drafts a blameless postmortem with open questions flagged — never publishes on its own.
Weekly sweep of ACM certs, KMS keys, and service-account tokens nearing expiry. Opens the rotation PR itself and pings the owner — before the pager does.
Starts with
Mon 09:00 weekly
Produces
rotation PR + alert
HOW TO USE A BLUEPRINT
Start with one bounded workflow.
Read the prerequisites. Identify services, permissions and data sources your implementation would need.
Inspect each transition. Separate the trigger, reasoning, verification and external action.
Test with fixtures first. Treat configuration and output blocks as illustrative reference material, then validate an implementation in an approved environment.