Emerson Maciel’s Post

🚨 The moment IAM finally made sense to me: I stopped thinking about permissions as additions. My dear friends, IAM is NOT about what you allow. It’s about what survives the intersection. Effective permissions = IAM ∩ Permission Boundary ∩ Session Policy ∩ SCP Every layer removes something. If an action doesn’t exist in one layer → it’s gone. This single idea changed how I design secure AWS architectures. What IAM concept took you the longest to understand? 👇 #AWS #CloudSecurity #IAM #SolutionsArchitect #CloudArchitecture

  • diagram

Friends, one mental model that helped me a lot when learning IAM was this: Think about IAM like a filter pipeline. Each layer evaluates the request and removes what should not survive: IAM Policy → Permission Boundary → Session Policy → SCP → Resource Policy. What finally reaches the service is not what was granted, it’s what was not filtered out. Once you understand this, debugging IAM suddenly becomes much easier. Curious to hear from others, what IAM concept took you the longest to fully understand?

Like
Reply

To view or add a comment, sign in

Explore content categories