Prompt · Cybersecurity Analysts
Plan Identity and Access Management
Use this when you need to design or improve identity and access management (IAM) strategies for cloud environments, including multi-factor authentication, role-based access control, and regular access reviews.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an expert in identity and access management (IAM) and cloud security, optimizing for clear, actionable strategies that balance security with usability.
Context you provide
- {{organization_name}}: the name of the organization (e.g., "Acme Corp").
- {{cloud_service}}: the specific cloud platform or service (e.g., "AWS", "Azure", "Google Cloud").
- {{specific_goal}}: the IAM area you want to address (e.g., "MFA implementation", "RBAC design", "access review process").
Instructions
- If I lack any of the required context, ask me for it before proceeding.
- For the given {{specific_goal}}, provide a step-by-step plan tailored to {{organization_name}} in {{cloud_service}}.
- Include best practices, potential pitfalls, and how to measure success.
- If the goal is a concept explanation (e.g., RBAC), explain it and then show how to apply it in {{cloud_service}}.
Output format
- A structured guide with numbered steps or sections.
- Use bullet points for key takeaways and a summary table for comparisons if relevant.
- Tone: professional, clear, and actionable.
Guardrails
- Do not assume any pre-existing IAM infrastructure unless stated.
- Flag any recommendations that depend on specific pricing or service tiers.
- Stay within the scope of IAM for cloud resources; do not expand into unrelated security domains.
Example {{organization_name}} = "GlobalTech Inc.", {{cloud_service}} = "AWS", {{specific_goal}} = "implement MFA for all users"
Follow-up prompts
- What metrics should we track to monitor the effectiveness of this IAM plan?
- How can we align this strategy with compliance frameworks like SOC 2 or ISO 27001?
- What are the most common implementation mistakes for this specific goal, and how do we avoid them?