CLOUD / A CONCEPT NOTE
IAM
who can do what on which resource
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
IAM (Identity and Access Management) is the policy engine for cloud platforms. A principal (user, role, or service account) attempts an action (like s3:GetObject) on a resource (like arn:aws:s3:::my-bucket/*). A policy document — JSON with Effect: Allow/Deny — either permits or denies the request.
02 / FOLLOW THE MECHANISM
How an IAM decision is made
Principal
makes an API call with their credentials (access key, OIDC token, or session).
Cloud IAM engine
collects all applicable policies: identity-based, resource-based, and organization SCPs.
Engine
evaluates policy statements in order: explicit Deny → explicit Allow → default Deny.
Engine
caches the decision for the duration of the credentials' TTL to avoid re-evaluating every call.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
test what actions a policy allows
aws iam simulate-principal-policy --policy-source-arn arn:aws:iam::123456789012:user/admin --action-names s3:ListBucketlist all custom IAM roles
gcloud iam roles list --project MY_PROJECT05 / CHECK YOURSELF
Could you explain IAM to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Cloud architectureServerlessrun code without provisioning or managing servers