The first useful slice
Compare two explicit JSON policy documents, match supported statements, and report added or removed action entries. Handle formatting changes without generating misleading noise.
A report with a defined scope
Statement: ReadReports Added action entry: s3:DeleteObject Removed action entries: none Structural comparison only. Effective AWS permissions not evaluated.
This is illustrative output. An action entry appearing in a document does not, by itself, establish a principal’s effective access.
Release sequence
Input validation, structural comparison, fixtures, and a readable local report.
Changed-policy detection and review output, with documented credential boundaries.
Integrate Access Analyzer results with clear scope and visibility into any AWS charges.
An easier way to explore synthetic examples using the same comparison library.
Have a policy-review workflow to share?
I’m looking for feedback on how engineers review application and deployment-role policies. Describe the workflow without sending credentials or confidential policies.