Security / REFERENCE BLUEPRINT

IAM Drift Sentinel

Every over-permissive IAM policy starts as a shortcut under deadline pressure. This loop catches the shortcut in real time, reasons about what the role actually uses, and hands you a scoped replacement as a reviewable PR. It never merges anything itself.

DESIGN INTENT

This is documentation for a proposed implementation. No automation runs from this page. Commands, configuration, output and timing are illustrative; package availability and measured performance have not been verified here.

THE LOOP / 5 STEPS

From the first signal to the final action.

  1. 01

    TRIGGER

    CloudTrail: PutRolePolicy / AttachRolePolicy

  2. 02

    GATE

    policy grants *:*, NotAction, or crosses account boundary

  3. 03

    REASON · AI

    classify blast radius against 90 days of Access Analyzer data

  4. 04

    VERIFY

    proposed policy replayed in IAM simulator — zero broken calls

  5. 05

    ACT

    Terraform PR with scoped policy + diff to #sec-alerts

01 / USAGE

How the intended workflow fits together

  1. 01

    Deploy once per AWS account. The sentinel subscribes to CloudTrail via EventBridge — no agents, no polling.

  2. 02

    When a risky policy lands, it pulls what the role actually did over 90 days and drafts the minimum policy that keeps every real call working.

  3. 03

    The draft is replayed through the IAM policy simulator. Only a clean replay produces a PR — anything ambiguous escalates to a human with full context.

02 / CONFIGURATION

Read the configuration contract

One YAML file per account. The gate keeps noise out; the escalation rule keeps the AI honest.

Illustrative configuration. Adapt only after verifying the implementation, schema and service permissions.

# sentinel.yaml
trigger:
  source: cloudtrail
  events: [PutRolePolicy, AttachRolePolicy]
gate:
  match: ["Action: '*'", "NotAction", "cross-account"]
reason:
  model: claude-sonnet
  context: access-analyzer:90d
  on_low_confidence: escalate   # never guess
act:
  pr: terraform/iam/
  notify: '#sec-alerts'

03 / EVIDENCE

What an output could look like

This authored example describes the intended result format. It is not evidence that a live run occurred.

$ iam-sentinel status
● watching 3 accounts · last event 2m ago

[Jul 06 11:42] PutRolePolicy on role/ci-deployer
  gate: matched  Action:'*' on s3
  reason: role used 4 of 214 granted actions (90d)
  verify: simulator replay OK — 0 broken calls
  act: PR #312 opened → terraform/iam/ci-deployer.tf

04 / IMPLEMENTATION REFERENCE

Review the setup sketch

The original command sketch is preserved for design context. It is not a verified installation recipe. Confirm that the package or repository exists and review its implementation before running anything.

Show illustrative setup commands
brew install supraj/tap/iam-sentinel
iam-sentinel init --account 8842-xxxx --region ap-south-1