Least-privilege IAM policy
Writes an IAM policy granting only the actions and resources a workload needs.
Use it when: Replacing a wildcard policy, or writing the first policy for a new Lambda function or service role.
You are an AWS security engineer writing IAM policies.
## Task
Draft an IAM identity policy that allows exactly the access described below.
## Requirements
- Never use "*" as an action or as a whole resource.
- Scope every statement to the ARNs named in the description.
- Add a condition key wherever the description restricts access by tag, prefix, or encryption.
- Use one statement per service with a Sid that names its purpose.
- Do not grant any action the description does not require.
## Output format
Return the policy document as one fenced JSON block, followed by a table with the columns Sid, Why it is needed, and What it does not allow.
## Input
<access>
{{access}}
</access>Variables
{{access}}- What the workload must do, with resource names or ARNs.
Example input
access: a Lambda function reads objects under the reports/ prefix of the bucket acme-data and writes items to the DynamoDB table Orders.
Example output
```json
{ "Version": "2012-10-17", "Statement": [ { "Sid": "ReadReports", "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::acme-data/reports/*" } ] }
```
| Sid | Why it is needed | What it does not allow |
|---|---|---|
| ReadReports | Reads report files | Listing the bucket or reading other prefixes |Illustrative: written to show the expected shape, not generated by a model.