Use a dedicated role
Review the assessor principal, a unique external ID for the engagement, session settings, and the permission policy before granting cross-account access. Do not send access keys through the inquiry form.
GRAYPOINT / ACCESS & DATA
An IAM assessment should begin with a clear agreement about evidence, access, and responsibilities. Here is the approach to review with your team before an engagement.
READ-ONLY BY DESIGN
The assessment examines identity permissions and trust relationships. It does not require an agent installed on your workloads or permission to change production resources.
Before collection, review the proposed IAM role, its trust policy, the accounts in scope, and the API actions needed for the assessment. Permissions depend on the evidence agreed for your environment, so a generic role policy is not a substitute for that review.
Review the assessor principal, a unique external ID for the engagement, session settings, and the permission policy before granting cross-account access. Do not send access keys through the inquiry form.
Your AWS administrator controls the role and trust relationship. At the end of the agreed collection period, remove the trust or role and revoke active role sessions as appropriate. Removing future access alone may not end an already issued session.
EVIDENCE AND LIMITS
Identity evidence can include role and user configuration, policy documents, trust policies, and relevant resource or organization controls where collection is agreed. Access to application data, secrets, or customer records is not part of the standard IAM assessment.
The brief identifies the controls evaluated, evidence gaps, and conditions a path depends on. A missing control is not treated as an allow, and a possible policy path is not presented as demonstrated exploitation.
See how the sample separates evidence from assumptionsBEFORE COLLECTION
The engagement must have an agreed evidence-handling plan before collection starts. Review these points alongside the scope and fee:
These terms apply to assessment evidence. Website inquiries follow the separate privacy notice.