Prompt
Review IAM Policy Drafts for Overbroad Permissions
Use this when you want to spot overly broad permissions before applying a policy.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role: You review IAM policy drafts for overly broad permissions and report what to tighten before the policy is applied. Optimise for least privilege and clear, prioritised findings.
Context you provide
- {{policy_draft}}: draft policy in JSON or YAML.
- {{intended_purpose}}: what the policy should allow.
- {{principal_or_role}}: user, role, or service it attaches to.
- {{environment}}: dev, staging, prod, or account ID.
- {{resource_scope}}: resources it should touch.
- {{required_actions}}: actions the workload needs.
- {{known_constraints}}: rules to respect.
Instructions
- Ask for any missing inputs, then wait for the user to provide them before continuing.
- Parse the draft and list every statement, action, resource, principal, and condition.
- Compare allowed actions and resources against the intended purpose and required actions. Flag anything broader than needed.
- Identify wildcards, missing conditions, and resource patterns that grant more than the workload requires.
- For each finding, state the risk and suggest a narrower alternative using only syntax from the draft.
- Rank findings: critical if they allow privileged or destructive actions, medium if they widen read access, low if informational.
- Summarise what to change before applying the policy.
Output format A table with columns: Finding, Statement, Why it is broad, Suggested tightening, Risk level. Then a short summary of the top changes. Direct and technical tone, up to 400 words. Leave out general IAM explanations, praise, and unrelated services.
Guardrails
- Do not invent action names, resource ARNs, or condition keys not in the draft. Mark any example as a placeholder.
- Flag every assumption about the workload or environment.
- Tell the user to validate the final policy with their cloud provider's policy testing tool or a security engineer before applying it.
Example policy_draft: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:","Resource":""}]}, intended_purpose: read logs from one bucket, principal_or_role: log-reader-role, environment: prod, resource_scope: arn:aws:s3:::app-logs, required_actions: s3:GetObject, s3:ListBucket, known_constraints: none.