01 / USAGE
How the intended workflow fits together
- 01
Deploy once per AWS account. The sentinel subscribes to CloudTrail via EventBridge — no agents, no polling.
- 02
When a risky policy lands, it pulls what the role actually did over 90 days and drafts the minimum policy that keeps every real call working.
- 03
The draft is replayed through the IAM policy simulator. Only a clean replay produces a PR — anything ambiguous escalates to a human with full context.
02 / CONFIGURATION
Read the configuration contract
One YAML file per account. The gate keeps noise out; the escalation rule keeps the AI honest.
Illustrative configuration. Adapt only after verifying the implementation, schema and service permissions.
# sentinel.yaml
trigger:
source: cloudtrail
events: [PutRolePolicy, AttachRolePolicy]
gate:
match: ["Action: '*'", "NotAction", "cross-account"]
reason:
model: claude-sonnet
context: access-analyzer:90d
on_low_confidence: escalate # never guess
act:
pr: terraform/iam/
notify: '#sec-alerts'03 / EVIDENCE
What an output could look like
This authored example describes the intended result format. It is not evidence that a live run occurred.
$ iam-sentinel status
● watching 3 accounts · last event 2m ago
[Jul 06 11:42] PutRolePolicy on role/ci-deployer
gate: matched Action:'*' on s3
reason: role used 4 of 214 granted actions (90d)
verify: simulator replay OK — 0 broken calls
act: PR #312 opened → terraform/iam/ci-deployer.tf04 / IMPLEMENTATION REFERENCE
Review the setup sketch
The original command sketch is preserved for design context. It is not a verified installation recipe. Confirm that the package or repository exists and review its implementation before running anything.
Show illustrative setup commands
brew install supraj/tap/iam-sentinel
iam-sentinel init --account 8842-xxxx --region ap-south-1