AWS IAM Access Analyzer: Find Over-Privileged Coding-Agent Roles Before They Leak
Coding-agent tool roles accrete permissions until someone can s3:GetObject on every bucket "for RAG debugging." AWS IAM Access Analyzer finds unused privileges, external access, and policy issues before those roles leak into a credential incident. Distinct from GuardDuty (runtime threat) and Verified Permissions (app-level authZ): Access Analyzer is continuous IAM posture for the roles your agents assume.