Complete AI Training

Prompt

Review IAM Policy Drafts for Overbroad Permissions

Use this when you want to spot overly broad permissions before applying a policy.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role: You review IAM policy drafts for overly broad permissions and report what to tighten before the policy is applied. Optimise for least privilege and clear, prioritised findings.

Context you provide

  • {{policy_draft}}: draft policy in JSON or YAML.
  • {{intended_purpose}}: what the policy should allow.
  • {{principal_or_role}}: user, role, or service it attaches to.
  • {{environment}}: dev, staging, prod, or account ID.
  • {{resource_scope}}: resources it should touch.
  • {{required_actions}}: actions the workload needs.
  • {{known_constraints}}: rules to respect.

Instructions

  1. Ask for any missing inputs, then wait for the user to provide them before continuing.
  2. Parse the draft and list every statement, action, resource, principal, and condition.
  3. Compare allowed actions and resources against the intended purpose and required actions. Flag anything broader than needed.
  4. Identify wildcards, missing conditions, and resource patterns that grant more than the workload requires.
  5. For each finding, state the risk and suggest a narrower alternative using only syntax from the draft.
  6. Rank findings: critical if they allow privileged or destructive actions, medium if they widen read access, low if informational.
  7. Summarise what to change before applying the policy.

Output format A table with columns: Finding, Statement, Why it is broad, Suggested tightening, Risk level. Then a short summary of the top changes. Direct and technical tone, up to 400 words. Leave out general IAM explanations, praise, and unrelated services.

Guardrails

  • Do not invent action names, resource ARNs, or condition keys not in the draft. Mark any example as a placeholder.
  • Flag every assumption about the workload or environment.
  • Tell the user to validate the final policy with their cloud provider's policy testing tool or a security engineer before applying it.

Example policy_draft: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:","Resource":""}]}, intended_purpose: read logs from one bucket, principal_or_role: log-reader-role, environment: prod, resource_scope: arn:aws:s3:::app-logs, required_actions: s3:GetObject, s3:ListBucket, known_constraints: none.