> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tensor9.com/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS IAM

> Holds the users, groups, roles and JSON policies that decide which principal may call which AWS API on which resource.

**On this page**

* [Coverage by target cloud](#coverage-by-target-cloud)
* [How the targets compare](#how-the-targets-compare)
  * [Max adaptation](#max-adaptation)
  * [Infrastructure-only adaptation](#infrastructure-only-adaptation)
* [On Google Cloud, Azure, OCI, and Private Kubernetes](#on-google-cloud-azure-oci-and-private-kubernetes)
  * [Via Cedar](#via-cedar)
* [On Google Cloud](#on-google-cloud)
  * [Via IAM](#via-iam)
* [On Azure](#on-azure)
  * [Via IAM](#via-iam-2)
* [On OCI](#on-oci)
  * [Via OCI IAM](#via-oci-iam)

## Coverage by target cloud

| Target             | Available |
| ------------------ | --------- |
| Google Cloud       | ✓         |
| Azure              | ✓         |
| OCI                | ✓         |
| Private Kubernetes | ✓         |

## How the targets compare

Each row compares a capability of IAM with its adaptation on each target.
A dash means this row is not stated for that target.

### Max adaptation

| Capability                                       | IAM                                  | Google Cloud, Azure, OCI, and Private Kubernetes · Cedar        |
| ------------------------------------------------ | ------------------------------------ | --------------------------------------------------------------- |
| Adaptation mechanism                             | AWS-managed IAM and STS              | Max: IAM and STS requests                                       |
| Access keys and secret keys                      | AWS account and IAM user credentials | Appliance-issued logical-account credentials                    |
| Policy language · authoring                      | IAM JSON                             | Supported IAM JSON translated to Cedar                          |
| Evaluation model · enforcement                   | Explicit deny overrides allow        | Deny-wins in enforce mode                                       |
| Policy consistency · freshness and revocation    | AWS-managed propagation              | Eventually consistent                                           |
| Explicit deny wins                               | Yes - native                         | Yes - Cedar decision; enforce mode blocks                       |
| Condition keys                                   | Yes                                  | Partial - Time and selected DNS keys; separate trust conditions |
| Permissions boundaries                           | Yes                                  | No - Not enforced by local Cedar                                |
| Resource-based policies                          | Yes                                  | No - No general resource-policy evaluation in this IAM adapter  |
| Cross-account role assumption                    | Yes                                  | Partial - Configured local accounts and caller authorization    |
| Organizations SCPs                               | Yes                                  | No - Not enforced by this authorizer                            |
| Authorization diagnostics · denial investigation | CloudTrail and Access Analyzer       | Denial and would-be-denial diagnostics                          |
| API coverage                                     | full                                 | high                                                            |

### Infrastructure-only adaptation

| Capability           | IAM                     | Google Cloud · IAM                                 | Azure · IAM                                        | OCI · OCI IAM                                      |
| -------------------- | ----------------------- | -------------------------------------------------- | -------------------------------------------------- | -------------------------------------------------- |
| Adaptation mechanism | AWS-managed IAM and STS | Infrastructure only: native permission translation | Infrastructure only: native permission translation | Infrastructure only: native permission translation |
| API coverage         | full                    | partial                                            | partial                                            | partial                                            |

## On Google Cloud, Azure, OCI, and Private Kubernetes

### Via Cedar

| Operation                                                                                                               | Area                      | Support      | Depth        | Notes                                                                                                                                                                                        |
| ----------------------------------------------------------------------------------------------------------------------- | ------------------------- | ------------ | ------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CreatePolicy / GetPolicy / ListPolicies / DeletePolicy                                                                  | Customer-managed policies | Supported    | Common       | Uses the deployment's customer-managed policy records; the runtime AWS-managed policy catalog is not supplied.                                                                               |
| CreatePolicyVersion / GetPolicyVersion / ListPolicyVersions / SetDefaultPolicyVersion / DeletePolicyVersion             | Customer-managed policies | Supported    | Most usage   | Maintains policy versions and the default version; up to five versions per policy.                                                                                                           |
| TagPolicy / UntagPolicy / ListPolicyTags                                                                                | Customer-managed policies | Supported    | Most usage   | -                                                                                                                                                                                            |
| PutRolePolicy / GetRolePolicy / ListRolePolicies / DeleteRolePolicy                                                     | Inline role policies      | Supported    | Common       | Validates supported policy syntax; policy changes propagate eventually and may not affect authorization immediately after success.                                                           |
| AddRoleToInstanceProfile / RemoveRoleFromInstanceProfile                                                                | Instance profiles         | Supported    | Most usage   | Maintains the association used by compute workloads to obtain role credentials.                                                                                                              |
| CreateInstanceProfile / GetInstanceProfile / ListInstanceProfiles / ListInstanceProfilesForRole / DeleteInstanceProfile | Instance profiles         | Supported    | Most usage   | -                                                                                                                                                                                            |
| TagInstanceProfile / UntagInstanceProfile / ListInstanceProfileTags                                                     | Instance profiles         | Supported    | Most usage   | -                                                                                                                                                                                            |
| CreateOpenIDConnectProvider / GetOpenIDConnectProvider / ListOpenIDConnectProviders / DeleteOpenIDConnectProvider       | OIDC providers            | Supported    | Common       | Registers the providers used by web-identity federation.                                                                                                                                     |
| TagOpenIDConnectProvider / UntagOpenIDConnectProvider / ListOpenIDConnectProviderTags                                   | OIDC providers            | Supported    | Most usage   | -                                                                                                                                                                                            |
| UpdateOpenIDConnectProviderThumbprint / AddClientIDToOpenIDConnectProvider / RemoveClientIDFromOpenIDConnectProvider    | OIDC providers            | Supported    | Most usage   | -                                                                                                                                                                                            |
| Access Analyzer / credential reports / Access Advisor                                                                   | Out of scope              | Out of scope | Full surface | These AWS IAM tools are not implemented by the adapter.                                                                                                                                      |
| Users / groups / access-key administration / SAML federation                                                            | Out of scope              | Out of scope | Full surface | These administration and federation operations are not served.                                                                                                                               |
| AttachRolePolicy / DetachRolePolicy / ListAttachedRolePolicies / ListEntitiesForPolicy                                  | Policy attachments        | Supported    | Common       | Attaches customer-managed policies to roles and returns their recorded relationships.                                                                                                        |
| CreateRole / GetRole / ListRoles / DeleteRole                                                                           | Roles                     | Supported    | Common       | Creates and reads role records; deletion invalidates sessions bound to that role incarnation.                                                                                                |
| TagRole / UntagRole / ListRoleTags                                                                                      | Roles                     | Supported    | Most usage   | Stores role tags; this does not enable general PrincipalTag policy conditions.                                                                                                               |
| UpdateAssumeRolePolicy / UpdateRole / UpdateRoleDescription                                                             | Roles                     | Supported    | Most usage   | Updates role configuration. Trust is evaluated separately from Cedar identity-policy authorization.                                                                                          |
| AssumeRole                                                                                                              | STS                       | Supported    | Common       | Checks role trust and issues expiring credentials. Role chaining, session policies, ExternalId and MFA inputs are unsupported.                                                               |
| AssumeRoleWithWebIdentity                                                                                               | STS                       | Supported    | Common       | Verifies the OIDC token and role trust before issuing a session. Issuer discovery and signing-key retrieval may need network access.                                                         |
| GetCallerIdentity                                                                                                       | STS                       | Supported    | Common       | Returns account, ARN and user ID; an assumed-role session has an assumed-role ARN.                                                                                                           |
| SimulateCustomPolicy                                                                                                    | Simulation                | Out of scope | Full surface | The IAM administration endpoint does not implement ad-hoc policy simulation.                                                                                                                 |
| SimulatePrincipalPolicy                                                                                                 | Simulation                | Partial      | Most usage   | Only the separate workload-identity endpoint supports simulation for its configured principal, with a supplied policy evaluator and concrete resources; not the IAM administration endpoint. |

#### Max IAM and STS

Max adaptation serves AWS IAM and Security Token Service (STS) requests within each appliance. The adapter supports 50 IAM administration operations across roles, customer-managed policies, instance profiles and OIDC providers, plus `GetCallerIdentity`, `AssumeRole` and `AssumeRoleWithWebIdentity`. Applications keep the supported AWS request formats.

Each appliance has its own identities, policies and authorization state. Appliances do not share policies or distribute policy updates to one another. Policy updates reach only the relevant replicas within the same appliance; changing permissions in one appliance does not change permissions in another.

Account IDs in adapted resource ARNs identify logical accounts within the appliance. These account records do not create cloud-provider accounts or billing relationships and do not provide AWS Organizations governance.

Cedar is the policy engine underpinning the adapter's authorization decisions. Tensor9's adapter handles IAM administration, STS credential exchanges and the translation of supported IAM policies into Cedar rules. Cedar evaluates those rules for requests handled by receiving adapters. Role trust is evaluated separately when a session is created.

Native permission translation is a different choice: it converts declared permissions into the target cloud's grants during provisioning and does not itself serve AWS IAM administration calls.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjcwIiB2aWV3Qm94PSIwIDAgODM2IDI3MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJJQU0gYWRtaW5pc3RyYXRpb24sIFNUUyB0cnVzdCBhbmQgcmVxdWVzdCBhdXRob3JpemF0aW9uIGhhdmUgc2VwYXJhdGUgcmVzcG9uc2liaWxpdGllcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT4KPGRlZnM+PG1hcmtlciBpZD0iaWFtLXBhdGgiIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjciIG1hcmtlckhlaWdodD0iNyIgb3JpZW50PSJhdXRvIj48cGF0aCBkPSJNMCwwIEwxMCw1IEwwLDEwIHoiIGZpbGw9IiM5NGEzYjgiLz48L21hcmtlcj48L2RlZnM+Cjx0ZXh0IHg9IjI0IiB5PSIyNCIgc3R5bGU9ImZvbnQ6IDcwMCAxMHB4IEludGVyLCBzYW5zLXNlcmlmOyBsZXR0ZXItc3BhY2luZzogMS4zcHg7IGZpbGw6ICM5NGEzYjgiPldJVEhJTiBPTkUgQVBQTElBTkNFPC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iNDAiIHdpZHRoPSIyMjQiIGhlaWdodD0iNTgiIHJ4PSIxMCIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjEzNiIgeT0iNjQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5JQU0gYWRtaW5pc3RyYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjEzNiIgeT0iODQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5yb2xlcyDCtyBwb2xpY2llcyDCtyBwcm92aWRlcnM8L3RleHQ+CjxsaW5lIHgxPSIyNDgiIHkxPSI2OSIgeDI9IjI5OCIgeTI9IjY5IiBzdHJva2U9IiM5NGEzYjgiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCNpYW0tcGF0aCkiLz4KPHJlY3QgeD0iMzAyIiB5PSI0MCIgd2lkdGg9IjIzMCIgaGVpZ2h0PSI1OCIgcng9IjEwIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDE3IiB5PSI2NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPlZhbGlkYXRlIGFuZCByZWNvcmQgZWRpdHM8L3RleHQ+Cjx0ZXh0IHg9IjQxNyIgeT0iODQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPnByb3RlY3RlZCBtYW5hZ2VtZW50IGFjY2VzczwvdGV4dD4KPGxpbmUgeDE9IjUzMiIgeTE9IjY5IiB4Mj0iNTgyIiB5Mj0iNjkiIHN0cm9rZT0iIzk0YTNiOCIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI2lhbS1wYXRoKSIvPgo8cmVjdCB4PSI1ODYiIHk9IjQwIiB3aWR0aD0iMjI2IiBoZWlnaHQ9IjU4IiByeD0iMTAiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI2OTkiIHk9IjY0IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+UmVhbGl6ZSB0aGUgY2hhbmdlPC90ZXh0Pgo8dGV4dCB4PSI2OTkiIHk9Ijg0IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+aWRlbnRpdGllcyBhbmQgcG9saWN5IHVwZGF0ZXM8L3RleHQ+CjxyZWN0IHg9IjI0IiB5PSIxMTYiIHdpZHRoPSIyMjQiIGhlaWdodD0iNTgiIHJ4PSIxMCIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjEzNiIgeT0iMTQwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+U1RTIHJvbGUgYXNzdW1wdGlvbjwvdGV4dD4KPHRleHQgeD0iMTM2IiB5PSIxNjAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5jYWxsZXIgY3JlZGVudGlhbHMgb3IgT0lEQyB0b2tlbjwvdGV4dD4KPGxpbmUgeDE9IjI0OCIgeTE9IjE0NSIgeDI9IjI5OCIgeTI9IjE0NSIgc3Ryb2tlPSIjOTRhM2I4IiBzdHJva2Utd2lkdGg9IjIiIG1hcmtlci1lbmQ9InVybCgjaWFtLXBhdGgpIi8+CjxyZWN0IHg9IjMwMiIgeT0iMTE2IiB3aWR0aD0iMjMwIiBoZWlnaHQ9IjU4IiByeD0iMTAiIGZpbGw9IiNlY2ZkZjUiIHN0cm9rZT0iIzA1OTY2OSIvPgo8dGV4dCB4PSI0MTciIHk9IjE0MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPlZlcmlmeSBpZGVudGl0eSBhbmQgcm9sZSB0cnVzdDwvdGV4dD4KPHRleHQgeD0iNDE3IiB5PSIxNjAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPnRydXN0IGNvbnRyb2xzIHNlc3Npb24gY3JlYXRpb248L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxNDUiIHgyPSI1ODIiIHkyPSIxNDUiIHN0cm9rZT0iIzk0YTNiOCIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI2lhbS1wYXRoKSIvPgo8cmVjdCB4PSI1ODYiIHk9IjExNiIgd2lkdGg9IjIyNiIgaGVpZ2h0PSI1OCIgcng9IjEwIiBmaWxsPSIjZmZmIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNjk5IiB5PSIxNDAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5UZW1wb3JhcnkgY3JlZGVudGlhbHM8L3RleHQ+Cjx0ZXh0IHg9IjY5OSIgeT0iMTYwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+cm9sZSBzZXNzaW9uIHdpdGggYW4gZXhwaXJ5PC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iMTkyIiB3aWR0aD0iMjI0IiBoZWlnaHQ9IjU4IiByeD0iMTAiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSIxMzYiIHk9IjIxNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPlN1cHBvcnRlZCBBV1Mgc2VydmljZSBjYWxsPC90ZXh0Pgo8dGV4dCB4PSIxMzYiIHk9IjIzNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPnNpZ25lZCB3aXRoIHNlc3Npb24gY3JlZGVudGlhbHM8L3RleHQ+CjxsaW5lIHgxPSIyNDgiIHkxPSIyMjEiIHgyPSIyOTgiIHkyPSIyMjEiIHN0cm9rZT0iIzk0YTNiOCIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI2lhbS1wYXRoKSIvPgo8cmVjdCB4PSIzMDIiIHk9IjE5MiIgd2lkdGg9IjIzMCIgaGVpZ2h0PSI1OCIgcng9IjEwIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDE3IiB5PSIyMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5WZXJpZnkgYW5kIGF1dGhvcml6ZTwvdGV4dD4KPHRleHQgeD0iNDE3IiB5PSIyMzYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPmF2YWlsYWJsZSBwb2xpY2llcyArIENlZGFyPC90ZXh0Pgo8bGluZSB4MT0iNTMyIiB5MT0iMjIxIiB4Mj0iNTgyIiB5Mj0iMjIxIiBzdHJva2U9IiM5NGEzYjgiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCNpYW0tcGF0aCkiLz4KPHJlY3QgeD0iNTg2IiB5PSIxOTIiIHdpZHRoPSIyMjYiIGhlaWdodD0iNTgiIHJ4PSIxMCIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjY5OSIgeT0iMjE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+UmVzdWx0IG9yIHNlcnZpY2UgZXJyb3I8L3RleHQ+Cjx0ZXh0IHg9IjY5OSIgeT0iMjM2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+ZW5mb3JjZSBtb2RlIGJsb2NrcyBkZW5pYWxzPC90ZXh0Pgo8L3N2Zz4=" alt="IAM administration, STS trust and request authorization have separate responsibilities." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjcwIiB2aWV3Qm94PSIwIDAgODM2IDI3MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJJQU0gYWRtaW5pc3RyYXRpb24sIFNUUyB0cnVzdCBhbmQgcmVxdWVzdCBhdXRob3JpemF0aW9uIGhhdmUgc2VwYXJhdGUgcmVzcG9uc2liaWxpdGllcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT4KPGRlZnM+PG1hcmtlciBpZD0iaWFtLXBhdGgiIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjciIG1hcmtlckhlaWdodD0iNyIgb3JpZW50PSJhdXRvIj48cGF0aCBkPSJNMCwwIEwxMCw1IEwwLDEwIHoiIGZpbGw9IiM5NGEzYjgiLz48L21hcmtlcj48L2RlZnM+Cjx0ZXh0IHg9IjI0IiB5PSIyNCIgc3R5bGU9ImZvbnQ6IDcwMCAxMHB4IEludGVyLCBzYW5zLXNlcmlmOyBsZXR0ZXItc3BhY2luZzogMS4zcHg7IGZpbGw6ICM5NGEzYjgiPldJVEhJTiBPTkUgQVBQTElBTkNFPC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iNDAiIHdpZHRoPSIyMjQiIGhlaWdodD0iNTgiIHJ4PSIxMCIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjEzNiIgeT0iNjQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5JQU0gYWRtaW5pc3RyYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjEzNiIgeT0iODQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5yb2xlcyDCtyBwb2xpY2llcyDCtyBwcm92aWRlcnM8L3RleHQ+CjxsaW5lIHgxPSIyNDgiIHkxPSI2OSIgeDI9IjI5OCIgeTI9IjY5IiBzdHJva2U9IiM0MTRlNjIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCNpYW0tcGF0aCkiLz4KPHJlY3QgeD0iMzAyIiB5PSI0MCIgd2lkdGg9IjIzMCIgaGVpZ2h0PSI1OCIgcng9IjEwIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDE3IiB5PSI2NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPlZhbGlkYXRlIGFuZCByZWNvcmQgZWRpdHM8L3RleHQ+Cjx0ZXh0IHg9IjQxNyIgeT0iODQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPnByb3RlY3RlZCBtYW5hZ2VtZW50IGFjY2VzczwvdGV4dD4KPGxpbmUgeDE9IjUzMiIgeTE9IjY5IiB4Mj0iNTgyIiB5Mj0iNjkiIHN0cm9rZT0iIzQxNGU2MiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI2lhbS1wYXRoKSIvPgo8cmVjdCB4PSI1ODYiIHk9IjQwIiB3aWR0aD0iMjI2IiBoZWlnaHQ9IjU4IiByeD0iMTAiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI2OTkiIHk9IjY0IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+UmVhbGl6ZSB0aGUgY2hhbmdlPC90ZXh0Pgo8dGV4dCB4PSI2OTkiIHk9Ijg0IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+aWRlbnRpdGllcyBhbmQgcG9saWN5IHVwZGF0ZXM8L3RleHQ+CjxyZWN0IHg9IjI0IiB5PSIxMTYiIHdpZHRoPSIyMjQiIGhlaWdodD0iNTgiIHJ4PSIxMCIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjEzNiIgeT0iMTQwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+U1RTIHJvbGUgYXNzdW1wdGlvbjwvdGV4dD4KPHRleHQgeD0iMTM2IiB5PSIxNjAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5jYWxsZXIgY3JlZGVudGlhbHMgb3IgT0lEQyB0b2tlbjwvdGV4dD4KPGxpbmUgeDE9IjI0OCIgeTE9IjE0NSIgeDI9IjI5OCIgeTI9IjE0NSIgc3Ryb2tlPSIjNDE0ZTYyIiBzdHJva2Utd2lkdGg9IjIiIG1hcmtlci1lbmQ9InVybCgjaWFtLXBhdGgpIi8+CjxyZWN0IHg9IjMwMiIgeT0iMTE2IiB3aWR0aD0iMjMwIiBoZWlnaHQ9IjU4IiByeD0iMTAiIGZpbGw9IiMxYTMxMjYiIHN0cm9rZT0iIzA1OTY2OSIvPgo8dGV4dCB4PSI0MTciIHk9IjE0MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPlZlcmlmeSBpZGVudGl0eSBhbmQgcm9sZSB0cnVzdDwvdGV4dD4KPHRleHQgeD0iNDE3IiB5PSIxNjAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPnRydXN0IGNvbnRyb2xzIHNlc3Npb24gY3JlYXRpb248L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxNDUiIHgyPSI1ODIiIHkyPSIxNDUiIHN0cm9rZT0iIzQxNGU2MiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI2lhbS1wYXRoKSIvPgo8cmVjdCB4PSI1ODYiIHk9IjExNiIgd2lkdGg9IjIyNiIgaGVpZ2h0PSI1OCIgcng9IjEwIiBmaWxsPSIjMjYyNjI2IiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNjk5IiB5PSIxNDAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5UZW1wb3JhcnkgY3JlZGVudGlhbHM8L3RleHQ+Cjx0ZXh0IHg9IjY5OSIgeT0iMTYwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+cm9sZSBzZXNzaW9uIHdpdGggYW4gZXhwaXJ5PC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iMTkyIiB3aWR0aD0iMjI0IiBoZWlnaHQ9IjU4IiByeD0iMTAiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSIxMzYiIHk9IjIxNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPlN1cHBvcnRlZCBBV1Mgc2VydmljZSBjYWxsPC90ZXh0Pgo8dGV4dCB4PSIxMzYiIHk9IjIzNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPnNpZ25lZCB3aXRoIHNlc3Npb24gY3JlZGVudGlhbHM8L3RleHQ+CjxsaW5lIHgxPSIyNDgiIHkxPSIyMjEiIHgyPSIyOTgiIHkyPSIyMjEiIHN0cm9rZT0iIzQxNGU2MiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI2lhbS1wYXRoKSIvPgo8cmVjdCB4PSIzMDIiIHk9IjE5MiIgd2lkdGg9IjIzMCIgaGVpZ2h0PSI1OCIgcng9IjEwIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDE3IiB5PSIyMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5WZXJpZnkgYW5kIGF1dGhvcml6ZTwvdGV4dD4KPHRleHQgeD0iNDE3IiB5PSIyMzYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPmF2YWlsYWJsZSBwb2xpY2llcyArIENlZGFyPC90ZXh0Pgo8bGluZSB4MT0iNTMyIiB5MT0iMjIxIiB4Mj0iNTgyIiB5Mj0iMjIxIiBzdHJva2U9IiM0MTRlNjIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCNpYW0tcGF0aCkiLz4KPHJlY3QgeD0iNTg2IiB5PSIxOTIiIHdpZHRoPSIyMjYiIGhlaWdodD0iNTgiIHJ4PSIxMCIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjY5OSIgeT0iMjE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+UmVzdWx0IG9yIHNlcnZpY2UgZXJyb3I8L3RleHQ+Cjx0ZXh0IHg9IjY5OSIgeT0iMjM2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+ZW5mb3JjZSBtb2RlIGJsb2NrcyBkZW5pYWxzPC90ZXh0Pgo8L3N2Zz4=" alt="IAM administration, STS trust and request authorization have separate responsibilities." />
</div>

<p className="t9-caption">IAM edits, STS trust checks and downstream authorization are separate steps.</p>

#### Access keys and secret keys

Max adaptation supports access keys and secret keys on Google Cloud, Azure, OCI and Private Kubernetes. Use the appliance-issued pair supplied by your appliance administrator with your AWS SDK or CLI. Configure `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, the appliance endpoint and its signing region. Supported service requests use AWS Signature Version 4 (SigV4); the receiving adapter verifies the signature and resolves the configured credential's account.

This long-term pair identifies a logical account root within the appliance, not an IAM user or a cloud-provider account. Keep the secret when it is issued; it is shown once. It is not valid at AWS endpoints or in another appliance. Native permission translation does not issue this runtime credential.

A long-term pair has no session token. Temporary credentials from the supported STS operations identify a role session and also require `AWS_SESSION_TOKEN`; they expire. Credential use does not provide IAM user access-key administration: `CreateAccessKey`, `ListAccessKeys`, `UpdateAccessKey` and `DeleteAccessKey` are unsupported. The combined IAM and STS management endpoint has the separate protected-access boundary described below.

#### Authentication and management access

Temporary credentials identify a verified role session. Receiving adapters verify the request signature, session validity and account before using that identity for authorization. `GetCallerIdentity` returns the account, ARN and user ID; an assumed-role session has an assumed-role ARN, not simply its role's IAM ARN.

Protect the combined IAM and STS management endpoint with authenticated deployment access. Requests without issued session credentials use its configured bootstrap caller; this endpoint is not a general lookup of arbitrary AWS access keys. The separate public web-identity route accepts only `AssumeRoleWithWebIdentity` and verifies the token before issuing credentials.

Configure authorization enforcement on receiving adapters. In enforce mode, a denied decision stops the operation and returns the receiving service's error. Report-only mode records would-be denials without blocking requests. Policy propagation does not turn report-only mode into enforcement.

#### Policy authoring and runtime changes

Keep authoring supported policies in IAM JSON. Declared stack policies and runtime IAM operations are separate ways to supply them. IAM reads return stored role, policy and relationship records, not documents reconstructed from compiled Cedar rules.

Runtime policy edits are validated before acceptance. Accepted changes update IAM records and propagate to the policy state used for authorization. Recording a change and observing its effect on a later request are not the same event.

Creating a non-default managed-policy version does not change effective permissions. Making it the default changes the version used by attached roles. Inline policies and policy attachments also affect permissions. Role-trust changes instead govern future session creation; they are evaluated separately from Cedar identity policies.

IAM `Allow` statements translate to Cedar `permit` rules and `Deny` statements to `forbid` rules. Supported actions, resource ARNs and conditions determine their scope. On the Cedar authorization path, unsupported restrictions are refused rather than silently dropped. Role trust remains a separate IAM-policy evaluation.

#### Eventual consistency for policy changes

IAM policy changes are eventually consistent, as in AWS IAM. Policy consistency is not customer-configurable. Changes take time to reach reads and authorization checks, including updates made through another replica in the same appliance.

A successful IAM response does not guarantee that subsequent reads or authorization checks already reflect the change. New grants may not be usable immediately, and revoked permissions may remain effective until the change propagates. With enforcement enabled, a request is blocked when the policies used for that check deny it; those policies can still be older than the latest accepted edit. Work already authorized can continue. Other appliances keep their own policies.

An error or timeout after commit does not imply rollback. The change may have committed even though the caller did not receive success; do not treat a failed response as proof that the old permissions remain in effect.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMzAwIiB2aWV3Qm94PSIwIDAgODM2IDMwMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJXaXRoaW4gb25lIGFwcGxpYW5jZSwgcG9saWN5IHByb3BhZ2F0aW9uIG1heSBjb250aW51ZSBhZnRlciBhIHN1Y2Nlc3NmdWwgSUFNIHJlc3BvbnNlLiBWZXJpZnkgdGhlIGRlcGVuZGVudCBvcGVyYXRpb247IG9uZSByZXN1bHQgZG9lcyBub3QgcHJvdmUgZXZlcnkgcmVwbGljYSBpcyB1cCB0byBkYXRlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJpYW0tcHJvcGFnYXRpb24iIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjciIG1hcmtlckhlaWdodD0iNyIgb3JpZW50PSJhdXRvIj48cGF0aCBkPSJNMCwwIEwxMCw1IEwwLDEwIHoiIGZpbGw9IiM5NGEzYjgiLz48L21hcmtlcj48L2RlZnM+Cjx0ZXh0IHg9IjI0IiB5PSIyNiIgc3R5bGU9ImZvbnQ6IDcwMCAxMHB4IEludGVyLCBzYW5zLXNlcmlmOyBsZXR0ZXItc3BhY2luZzogMS4zcHg7IGZpbGw6ICM5NGEzYjgiPk9ORSBBUFBMSUFOQ0UgwrcgUE9MSUNZIENIQU5HRVMgVEFLRSBUSU1FIFRPIFBST1BBR0FURTwvdGV4dD4KPHJlY3QgeD0iMjQiIHk9IjQ4IiB3aWR0aD0iMjE4IiBoZWlnaHQ9Ijk4IiByeD0iMTIiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSIxMzMiIHk9Ijc4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+U3VjY2Vzc2Z1bCBJQU0gcmVzcG9uc2U8L3RleHQ+Cjx0ZXh0IHg9IjEzMyIgeT0iMTA0IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+Q2hhbmdlIGFjY2VwdGVkPC90ZXh0Pgo8dGV4dCB4PSIxMzMiIHk9IjEyNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPk5vdCBwcm9vZiBvZiBwcm9wYWdhdGlvbjwvdGV4dD4KPGxpbmUgeDE9IjI0MiIgeTE9Ijk3IiB4Mj0iMzAwIiB5Mj0iOTciIHN0cm9rZT0iIzk0YTNiOCIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI2lhbS1wcm9wYWdhdGlvbikiLz4KPHJlY3QgeD0iMzA0IiB5PSI0OCIgd2lkdGg9IjUwOCIgaGVpZ2h0PSI5OCIgcng9IjEyIiBmaWxsPSIjZmZmYmViIiBzdHJva2U9IiNmNTllMGIiLz4KPHRleHQgeD0iMzI2IiB5PSI3OCIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPlByb3BhZ2F0aW9uIG1heSBjb250aW51ZTwvdGV4dD4KPHRleHQgeD0iMzI2IiB5PSIxMDQiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5OZXcgZ3JhbnRzIG1heSBub3Qgd29yayB5ZXQ8L3RleHQ+Cjx0ZXh0IHg9IjMyNiIgeT0iMTI2IiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+UmV2b2tlZCBwZXJtaXNzaW9ucyBtYXkgc3RpbGwgYWxsb3c8L3RleHQ+CjxsaW5lIHgxPSI1NTgiIHkxPSIxNDYiIHgyPSI1NTgiIHkyPSIxNzYiIHN0cm9rZT0iIzk0YTNiOCIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI2lhbS1wcm9wYWdhdGlvbikiLz4KPHJlY3QgeD0iMjQiIHk9IjE4MCIgd2lkdGg9Ijc4OCIgaGVpZ2h0PSI4MiIgcng9IjEwIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDE4IiB5PSIyMDUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5WZXJpZnkgdGhlIGRlcGVuZGVudCBvcGVyYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjQxOCIgeT0iMjI3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTAuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5DaGVjayB0aGUgbmVlZGVkIHJlc3VsdCBiZWZvcmUgcmVseWluZyBvbiB0aGUgY2hhbmdlLjwvdGV4dD4KPHRleHQgeD0iNDE4IiB5PSIyNDgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPk9uZSByZXN1bHQgZG9lcyBub3QgcHJvdmUgZXZlcnkgcmVwbGljYSBpcyB1cCB0byBkYXRlLjwvdGV4dD4KPHRleHQgeD0iNDE4IiB5PSIyODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5ObyBmaXhlZCBwcm9wYWdhdGlvbiBkZWFkbGluZS4gT3RoZXIgYXBwbGlhbmNlcyBrZWVwIHRoZWlyIG93biBwb2xpY2llcy48L3RleHQ+Cjwvc3ZnPg==" alt="Within one appliance, policy propagation may continue after a successful IAM response. Verify the dependent operation; one result does not prove every replica is up to date." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMzAwIiB2aWV3Qm94PSIwIDAgODM2IDMwMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJXaXRoaW4gb25lIGFwcGxpYW5jZSwgcG9saWN5IHByb3BhZ2F0aW9uIG1heSBjb250aW51ZSBhZnRlciBhIHN1Y2Nlc3NmdWwgSUFNIHJlc3BvbnNlLiBWZXJpZnkgdGhlIGRlcGVuZGVudCBvcGVyYXRpb247IG9uZSByZXN1bHQgZG9lcyBub3QgcHJvdmUgZXZlcnkgcmVwbGljYSBpcyB1cCB0byBkYXRlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJpYW0tcHJvcGFnYXRpb24iIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjciIG1hcmtlckhlaWdodD0iNyIgb3JpZW50PSJhdXRvIj48cGF0aCBkPSJNMCwwIEwxMCw1IEwwLDEwIHoiIGZpbGw9IiM5NGEzYjgiLz48L21hcmtlcj48L2RlZnM+Cjx0ZXh0IHg9IjI0IiB5PSIyNiIgc3R5bGU9ImZvbnQ6IDcwMCAxMHB4IEludGVyLCBzYW5zLXNlcmlmOyBsZXR0ZXItc3BhY2luZzogMS4zcHg7IGZpbGw6ICM5NGEzYjgiPk9ORSBBUFBMSUFOQ0UgwrcgUE9MSUNZIENIQU5HRVMgVEFLRSBUSU1FIFRPIFBST1BBR0FURTwvdGV4dD4KPHJlY3QgeD0iMjQiIHk9IjQ4IiB3aWR0aD0iMjE4IiBoZWlnaHQ9Ijk4IiByeD0iMTIiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSIxMzMiIHk9Ijc4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+U3VjY2Vzc2Z1bCBJQU0gcmVzcG9uc2U8L3RleHQ+Cjx0ZXh0IHg9IjEzMyIgeT0iMTA0IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+Q2hhbmdlIGFjY2VwdGVkPC90ZXh0Pgo8dGV4dCB4PSIxMzMiIHk9IjEyNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPk5vdCBwcm9vZiBvZiBwcm9wYWdhdGlvbjwvdGV4dD4KPGxpbmUgeDE9IjI0MiIgeTE9Ijk3IiB4Mj0iMzAwIiB5Mj0iOTciIHN0cm9rZT0iIzQxNGU2MiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI2lhbS1wcm9wYWdhdGlvbikiLz4KPHJlY3QgeD0iMzA0IiB5PSI0OCIgd2lkdGg9IjUwOCIgaGVpZ2h0PSI5OCIgcng9IjEyIiBmaWxsPSIjMzEyZDFhIiBzdHJva2U9IiNmNTllMGIiLz4KPHRleHQgeD0iMzI2IiB5PSI3OCIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPlByb3BhZ2F0aW9uIG1heSBjb250aW51ZTwvdGV4dD4KPHRleHQgeD0iMzI2IiB5PSIxMDQiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5OZXcgZ3JhbnRzIG1heSBub3Qgd29yayB5ZXQ8L3RleHQ+Cjx0ZXh0IHg9IjMyNiIgeT0iMTI2IiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+UmV2b2tlZCBwZXJtaXNzaW9ucyBtYXkgc3RpbGwgYWxsb3c8L3RleHQ+CjxsaW5lIHgxPSI1NTgiIHkxPSIxNDYiIHgyPSI1NTgiIHkyPSIxNzYiIHN0cm9rZT0iIzQxNGU2MiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI2lhbS1wcm9wYWdhdGlvbikiLz4KPHJlY3QgeD0iMjQiIHk9IjE4MCIgd2lkdGg9Ijc4OCIgaGVpZ2h0PSI4MiIgcng9IjEwIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDE4IiB5PSIyMDUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5WZXJpZnkgdGhlIGRlcGVuZGVudCBvcGVyYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjQxOCIgeT0iMjI3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTAuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5DaGVjayB0aGUgbmVlZGVkIHJlc3VsdCBiZWZvcmUgcmVseWluZyBvbiB0aGUgY2hhbmdlLjwvdGV4dD4KPHRleHQgeD0iNDE4IiB5PSIyNDgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPk9uZSByZXN1bHQgZG9lcyBub3QgcHJvdmUgZXZlcnkgcmVwbGljYSBpcyB1cCB0byBkYXRlLjwvdGV4dD4KPHRleHQgeD0iNDE4IiB5PSIyODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5ObyBmaXhlZCBwcm9wYWdhdGlvbiBkZWFkbGluZS4gT3RoZXIgYXBwbGlhbmNlcyBrZWVwIHRoZWlyIG93biBwb2xpY2llcy48L3RleHQ+Cjwvc3ZnPg==" alt="Within one appliance, policy propagation may continue after a successful IAM response. Verify the dependent operation; one result does not prove every replica is up to date." />
</div>

<p className="t9-caption">Success can precede propagation. A dependent-operation check is not a freshness guarantee for every replica.</p>

#### Propagation and dependent workflows

Verify propagation before starting a workflow that depends on the change; a fixed sleep is not proof that propagation has completed. Check the relevant IAM state and the allowed or denied result needed by that workflow. One observed result does not prove that every replica is up to date or that the next request will observe the same policy state. Avoid putting IAM changes in a critical request path that assumes immediate visibility.

There is no fixed propagation deadline. An unavailable replica or policy service can delay visibility or make requests fail. Eventual consistency does not guarantee offline availability, and there is no universal rule that permissions become denied after a fixed cache age. Test propagation, failure and recovery across the appliance's replicas with the required enforcement settings.

#### Authorization decisions

Cedar evaluates the principal, action, resource and supported request context against the selected policies. Any matching `forbid` overrides a `permit`. With no matching permit, the decision is deny. Policy order does not change that decision.

These rules describe supported identity-policy authorization. IAM management also has a privileged account-root path, and STS uses separate trust checks. They do not imply that every AWS policy layer or every receiving service is covered.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjI2IiB2aWV3Qm94PSIwIDAgODM2IDIyNiIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJJbiBlbmZvcmNlIG1vZGUsIGEgbWF0Y2hpbmcgZGVueSBibG9ja3MgdGhlIHJlcXVlc3Q7IG90aGVyd2lzZSBhIG1hdGNoaW5nIGFsbG93IHBlcm1pdHMgaXQsIGFuZCB0aGUgZGVmYXVsdCBpcyBkZW55LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJpYW0tZGVueSIgdmlld0JveD0iMCAwIDEwIDEwIiByZWZYPSI4IiByZWZZPSI1IiBtYXJrZXJXaWR0aD0iNyIgbWFya2VySGVpZ2h0PSI3IiBvcmllbnQ9ImF1dG8iPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzk0YTNiOCIvPjwvbWFya2VyPjwvZGVmcz4KPHRleHQgeD0iMjQiIHk9IjI0IiBzdHlsZT0iZm9udDogNzAwIDEwcHggSW50ZXIsIHNhbnMtc2VyaWY7IGxldHRlci1zcGFjaW5nOiAxLjNweDsgZmlsbDogIzk0YTNiOCI+RU5GT1JDRSBNT0RFIMK3IFBPTElDWSBPUkRFUiBET0VTIE5PVCBDSEFOR0UgVEhFIERFQ0lTSU9OPC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iNjIiIHdpZHRoPSIyMTgiIGhlaWdodD0iMTAwIiByeD0iMTIiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSIxMzMiIHk9Ijg4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+VmVyaWZpZWQgcmVxdWVzdDwvdGV4dD4KPHRleHQgeD0iMTMzIiB5PSIxMTIiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5wcmluY2lwYWwgwrcgYWN0aW9uIMK3IHJlc291cmNlPC90ZXh0Pgo8dGV4dCB4PSIxMzMiIHk9IjEzNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPnN1cHBvcnRlZCBjb25kaXRpb24gY29udGV4dDwvdGV4dD4KPGxpbmUgeDE9IjI0MiIgeTE9IjExMiIgeDI9IjMwMCIgeTI9IjExMiIgc3Ryb2tlPSIjOTRhM2I4IiBzdHJva2Utd2lkdGg9IjIiIG1hcmtlci1lbmQ9InVybCgjaWFtLWRlbnkpIi8+CjxyZWN0IHg9IjMwNCIgeT0iNDAiIHdpZHRoPSI1MDgiIGhlaWdodD0iNDgiIHJ4PSIxMCIgZmlsbD0iI2ZmZmJlYiIgc3Ryb2tlPSIjZjU5ZTBiIi8+Cjx0ZXh0IHg9IjMyNCIgeT0iNjkiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5BIG1hdGNoaW5nIGZvcmJpZCDihpIgZGVueSwgZXZlbiBpZiBhIHBlcm1pdCBhbHNvIG1hdGNoZXM8L3RleHQ+CjxyZWN0IHg9IjMwNCIgeT0iOTgiIHdpZHRoPSI1MDgiIGhlaWdodD0iNDgiIHJ4PSIxMCIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjMyNCIgeT0iMTI3IiBzdHlsZT0iZm9udDogNzAwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+Tm8gZm9yYmlkLCB3aXRoIGEgbWF0Y2hpbmcgcGVybWl0IOKGkiBhbGxvdzwvdGV4dD4KPHJlY3QgeD0iMzA0IiB5PSIxNTYiIHdpZHRoPSI1MDgiIGhlaWdodD0iNDgiIHJ4PSIxMCIgZmlsbD0iI2ZmZmJlYiIgc3Ryb2tlPSIjZjU5ZTBiIi8+Cjx0ZXh0IHg9IjMyNCIgeT0iMTg1IiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+Tm8gbWF0Y2hpbmcgcGVybWl0IOKGkiBkZW55PC90ZXh0Pgo8L3N2Zz4=" alt="In enforce mode, a matching deny blocks the request; otherwise a matching allow permits it, and the default is deny." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjI2IiB2aWV3Qm94PSIwIDAgODM2IDIyNiIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJJbiBlbmZvcmNlIG1vZGUsIGEgbWF0Y2hpbmcgZGVueSBibG9ja3MgdGhlIHJlcXVlc3Q7IG90aGVyd2lzZSBhIG1hdGNoaW5nIGFsbG93IHBlcm1pdHMgaXQsIGFuZCB0aGUgZGVmYXVsdCBpcyBkZW55LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJpYW0tZGVueSIgdmlld0JveD0iMCAwIDEwIDEwIiByZWZYPSI4IiByZWZZPSI1IiBtYXJrZXJXaWR0aD0iNyIgbWFya2VySGVpZ2h0PSI3IiBvcmllbnQ9ImF1dG8iPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzk0YTNiOCIvPjwvbWFya2VyPjwvZGVmcz4KPHRleHQgeD0iMjQiIHk9IjI0IiBzdHlsZT0iZm9udDogNzAwIDEwcHggSW50ZXIsIHNhbnMtc2VyaWY7IGxldHRlci1zcGFjaW5nOiAxLjNweDsgZmlsbDogIzk0YTNiOCI+RU5GT1JDRSBNT0RFIMK3IFBPTElDWSBPUkRFUiBET0VTIE5PVCBDSEFOR0UgVEhFIERFQ0lTSU9OPC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iNjIiIHdpZHRoPSIyMTgiIGhlaWdodD0iMTAwIiByeD0iMTIiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSIxMzMiIHk9Ijg4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+VmVyaWZpZWQgcmVxdWVzdDwvdGV4dD4KPHRleHQgeD0iMTMzIiB5PSIxMTIiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5wcmluY2lwYWwgwrcgYWN0aW9uIMK3IHJlc291cmNlPC90ZXh0Pgo8dGV4dCB4PSIxMzMiIHk9IjEzNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPnN1cHBvcnRlZCBjb25kaXRpb24gY29udGV4dDwvdGV4dD4KPGxpbmUgeDE9IjI0MiIgeTE9IjExMiIgeDI9IjMwMCIgeTI9IjExMiIgc3Ryb2tlPSIjNDE0ZTYyIiBzdHJva2Utd2lkdGg9IjIiIG1hcmtlci1lbmQ9InVybCgjaWFtLWRlbnkpIi8+CjxyZWN0IHg9IjMwNCIgeT0iNDAiIHdpZHRoPSI1MDgiIGhlaWdodD0iNDgiIHJ4PSIxMCIgZmlsbD0iIzMxMmQxYSIgc3Ryb2tlPSIjZjU5ZTBiIi8+Cjx0ZXh0IHg9IjMyNCIgeT0iNjkiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5BIG1hdGNoaW5nIGZvcmJpZCDihpIgZGVueSwgZXZlbiBpZiBhIHBlcm1pdCBhbHNvIG1hdGNoZXM8L3RleHQ+CjxyZWN0IHg9IjMwNCIgeT0iOTgiIHdpZHRoPSI1MDgiIGhlaWdodD0iNDgiIHJ4PSIxMCIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjMyNCIgeT0iMTI3IiBzdHlsZT0iZm9udDogNzAwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+Tm8gZm9yYmlkLCB3aXRoIGEgbWF0Y2hpbmcgcGVybWl0IOKGkiBhbGxvdzwvdGV4dD4KPHJlY3QgeD0iMzA0IiB5PSIxNTYiIHdpZHRoPSI1MDgiIGhlaWdodD0iNDgiIHJ4PSIxMCIgZmlsbD0iIzMxMmQxYSIgc3Ryb2tlPSIjZjU5ZTBiIi8+Cjx0ZXh0IHg9IjMyNCIgeT0iMTg1IiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+Tm8gbWF0Y2hpbmcgcGVybWl0IOKGkiBkZW55PC90ZXh0Pgo8L3N2Zz4=" alt="In enforce mode, a matching deny blocks the request; otherwise a matching allow permits it, and the default is deny." />
</div>

<p className="t9-caption">Explicit deny overrides allow; without a matching allow, the decision is deny.</p>

#### Supported conditions

Identity policies support `aws:CurrentTime`, `aws:EpochTime`, and three Route 53 change keys: `route53:ChangeResourceRecordSetsNormalizedRecordNames`, `route53:ChangeResourceRecordSetsRecordTypes` and `route53:ChangeResourceRecordSetsActions`. The DNS subset includes supported set, wildcard, negation and existence tests. Accepted operators depend on the key.

`aws:SourceIp`, `aws:PrincipalTag`, `aws:SecureTransport` and MFA identity-policy keys are unsupported. A value being available in the deployment does not itself make its condition supported. Stored role tags do not imply general tag-based authorization.

Role-trust conditions are separate. OIDC trust supports issuer-qualified audience and subject comparisons using `StringEquals` and `StringLike`. Pod Identity trust supports those operators on its six verified request-tag keys. Neither capability adds general identity-policy condition coverage.

#### Role trust and temporary credentials

`AssumeRole` evaluates role trust before creating an expiring session. Conditional cross-account assumption is supported between accounts served by the same appliance when caller-side authorization and target-role trust both permit it. This does not provide cross-appliance trust or policy sharing. Account-root delegation and assumption into arbitrary real AWS accounts are outside this scope.

`AssumeRoleWithWebIdentity` verifies the token signature, issuer, audience, subject and expiry against a registered OIDC provider and evaluates role trust. The dedicated Pod Identity exchange verifies the agent and pod token, selects the role from its association and issues a session with attested tags. These are real credential exchanges, not static credentials derived from a role name.

Configured replicas within one appliance can share session verification. This does not make credentials valid in another appliance. Sessions expire and are tied to the role's identity, so deleting and recreating a role with the same name does not revive its old sessions. Trust changes govern future assumptions; permission changes affect later authorization checks as they propagate. Neither effect is guaranteed to be visible immediately after a successful IAM response.

Normal `AssumeRole` does not support role chaining, session policies, arbitrary session tags, ExternalId, MFA, SourceIdentity or ProvidedContexts. The trusted Pod Identity tag path is separate. Neither session issuance nor `GetCallerIdentity` calls AWS STS, but OIDC discovery and signing-key retrieval may require access to the configured issuer.

#### Administration and simulation scope

Administration includes role updates and tags; customer-managed policy creation, versions and tags; inline role policies and attachments; instance-profile lifecycle, membership and tags; and OIDC-provider lifecycle, audiences, thumbprints and tags. Policy versioning supports up to five versions per policy. AWS-managed policy documents are not supplied by the runtime catalog; use supported customer-managed policies.

The IAM administration endpoint does not implement `SimulatePrincipalPolicy` or `SimulateCustomPolicy`. A separate workload-identity endpoint supports restricted principal simulation when configured with a policy evaluator. That simulation uses its configured workload and explicit actions and resource ARNs; it does not accept arbitrary principals or ad-hoc policy documents. A simulated deny may differ from the allowed response in report-only mode.

User, group and access-key administration, SAML federation, service-linked roles, Access Analyzer, credential reports and Access Advisor are outside the implemented API scope.

#### Diagnostics and deployment

Authorization diagnostics record denials and would-be denials, including the principal, action, resource, result, enforcement mode and readiness. They do not record every successful permit or identify the matched policy statements. Policy validation and offline evaluation help test examples; they are not an Access Analyzer equivalent.

The IAM and STS endpoints and Cedar evaluation run within each appliance. There is no shared policy distribution mechanism between appliances. Use the target and deployment configuration supported for that environment; portable policy evaluation does not imply identical native identity provisioning on every cloud. AWS adapter permissions and the target cloud's native grants remain separate.

Tensor9 operates the adapter and policy propagation within each appliance. Diagnostic destinations and retention follow the appliance's logging configuration. Before cutover, test administration, denied requests, credential renewal, permission-change propagation and outages across that appliance's replicas. A healthy replica count does not prove that a particular policy change has reached every authorization check.

#### Limitations

△ Limitations

* **The policy language is a supported subset.** Identity-policy NotAction, NotResource and NotPrincipal are refused, as are policy variables, question-mark wildcards and unsupported principal forms. Action wildcards are limited to \* or service:\*; resource patterns support broader star matching. Resolve unsupported restrictions before using the Cedar authorization path.
* **Permissions boundaries are not enforced by local Cedar.** Role creation rejects a boundary unless explicitly acknowledged. Acknowledgment retains the attribute but does not enforce it; omitting this restriction can broaden permissions. Native AWS enforcement is a separate domain.
* **Resource-policy support belongs to the receiving service.** Do not assume that translating an identity policy also supplies resource-policy APIs or AWS resource/identity-policy combination rules.
* **Organizations SCPs are not enforced by this authorizer.** Account and organization restrictions are not added by successful IAM administration or token exchange.
* **Propagation and enforcement are separate.** New permissions can take time to become usable, and revoked permissions can remain effective during propagation. Report-only mode does not block denied requests even after the updated policy is visible.
* **Each appliance is independent.** Policies, policy updates and authorization state are not shared between appliances. Replica-shared credentials are confined to the same appliance and do not grant global AWS authority.

## On Google Cloud

### Via IAM

#### Infrastructure only: native permissions

Tensor9 translates the roles, policies, and attachments declared by your stack into Google Cloud IAM grants during provisioning. Google Cloud IAM binds predefined or custom roles to principals. Tensor9 maps supported AWS actions to permissions; the generated scope and supported condition mapping can differ. The resulting grants use predefined or custom role permissions and resource scopes.

#### Permission differences

AWS policies can restrict individual resources and request conditions. This mapping does not preserve every restriction. Mappings that broaden access require explicit acceptance; incompatible restrictions stop translation. Some mappings grant fewer permissions. Review generated actions and scopes before deployment. The Cedar-based adapter separately serves supported AWS IAM calls and evaluates supported AWS identity policies.

#### Application and identity changes

This mapping provisions grants; it does not serve runtime AWS IAM calls such as `iam:CreateRole` or `iam:AttachRolePolicy`. Replace references to AWS role ARNs in trust policies, assume-role calls, and resource policies with the appropriate Google identity. New target grants are created during deployment; AWS policy objects are not copied.

## On Azure

### Via IAM

#### Infrastructure only: native permissions

Tensor9 translates the roles, policies, and attachments declared by your stack into Azure RBAC and Entra grants during provisioning. Azure RBAC assigns built-in or custom roles over a scope hierarchy. Tensor9 maps supported actions and uses target assignment scopes; not every AWS resource or condition restriction is preserved. The resulting grants use role-assignment granularity.

#### Permission differences

AWS policies can restrict individual resources and request conditions. This mapping does not preserve every restriction. Mappings that broaden access require explicit acceptance; incompatible restrictions stop translation. Some mappings grant fewer permissions. Review generated actions and scopes before deployment. The Cedar-based adapter separately serves supported AWS IAM calls and evaluates supported AWS identity policies.

#### Application and identity changes

This mapping provisions grants; it does not serve runtime AWS IAM calls such as `iam:CreateRole` or `iam:AttachRolePolicy`. Replace references to AWS role ARNs in trust policies, assume-role calls, and resource policies with the appropriate Azure identity. New target grants are created during deployment; AWS policy objects are not copied.

## On OCI

### Via OCI IAM

#### Infrastructure only: native permissions

Tensor9 translates the roles, policies, and attachments declared by your stack into OCI IAM grants during provisioning. OCI IAM uses policy statements scoped to compartments and groups. This mapping uses OCI verbs and resource families, which can group AWS actions or resources differently. The resulting grants use group and compartment granularity.

#### Permission differences

AWS policies can restrict individual resources and request conditions. This mapping does not preserve every restriction. Mappings that broaden access require explicit acceptance; incompatible restrictions stop translation. Some mappings grant fewer permissions. Review generated actions and scopes before deployment. The Cedar-based adapter separately serves supported AWS IAM calls and evaluates supported AWS identity policies.

#### Application and identity changes

This mapping provisions grants; it does not serve runtime AWS IAM calls such as `iam:CreateRole` or `iam:AttachRolePolicy`. Replace references to AWS role ARNs in trust policies, assume-role calls, and resource policies with the appropriate OCI identity. New target grants are created during deployment; AWS policy objects are not copied.

[Service Catalog](/service-adapters/catalog).
