# P12 IAM access investigation workbook

Use with AWS237 and the supplied case packet. This is a read-only evidence review.

## 1. Question, authority and time

- Exact question (possible access, simulated decision, observed use, or all three):
- Incident/change ticket:
- Investigator and approver:
- Resource owner and principal owner:
- Account/organization zone of trust:
- Resource account and caller account:
- Region(s), UTC start/end and time synchronization:
- Data classification and redaction requirements:

## 2. Request tuple

Authorization cannot be investigated from a username alone.

| Field | Exact/redacted value | Source |
|---|---|---|
| principal/session ARN |  |  |
| action |  |  |
| resource ARN |  |  |
| requested Region/service endpoint |  |  |
| source IP/VPC/VPC endpoint |  |  |
| principal/resource/request/session tags |  |  |
| MFA, TLS, time and called-via context |  |  |
| role session name/source identity |  |  |

## 3. Effective-permission matrix

| Policy/control layer | Relevant allow | Relevant explicit deny | Implicit limit/missing allow | Version/source/time | Owner |
|---|---|---|---|---|---|
| identity policy |  |  |  |  |  |
| resource policy/ACL/access point |  |  |  |  |  |
| role trust policy |  |  |  |  |  |
| permissions boundary |  |  |  |  |  |
| STS session policy |  |  |  |  |  |
| SCP |  |  |  |  |  |
| RCP |  |  |  |  |  |
| VPC endpoint policy |  |  |  |  |  |
| KMS key policy/grant |  |  |  |  |  |
| service-specific guardrail |  |  |  |  |  |

Cross-account requests generally require permission on both the caller and
resource-owner sides. One applicable explicit deny overrides an allow.

## 4. Access Analyzer evidence

| Analyzer | Type | Account/organization scope | Region | Resource scope/window | Status/cost owner |
|---|---|---|---|---|---|
|  | external/internal/unused |  |  |  |  |

| Finding ID | Type/status | Resource/principal/access | Condition | Created/updated | Meaning | Gap/limitation |
|---|---|---|---|---|---|---|
|  |  |  |  |  |  |  |

- Why the principal is inside/outside the zone of trust:
- Supported resource type confirmed:
- Finding ACTIVE, ARCHIVED or RESOLVED and why:
- Archive rule reviewed; exception owner/expiry:
- Analyzer latency or error evidence:
- What this finding does **not** prove:

## 5. Policy validation and simulation

### Validation

| Policy type | Locale/type | ERROR | SECURITY_WARNING | WARNING | SUGGESTION | Resolution/accepted rationale |
|---|---|---:|---:|---:|---:|---|
|  |  |  |  |  |  |  |

### Simulation

| Principal/custom policy | Action | Resource | Supplied context keys | Missing context | Boundary/SCP/resource policy supplied | Result/matched statement |
|---|---|---|---|---|---|---|
|  |  |  |  |  |  |  |

- RCP omitted because simulator does not support it:
- Real resource policy was explicitly supplied or console-retrieved:
- Service-specific/KMS/VPC endpoint gaps:
- Predicted result and confidence:
- Safe live verification plan, if separately approved:

## 6. CloudTrail investigation

| Source | Event coverage | Account/Region | Retention | Integrity/encryption | Query owner |
|---|---|---|---|---|---|
| Event history | management only |  | 90 days | service-managed history |  |
| trail | management/data/network chosen |  |  | validation/KMS |  |
| Lake event data store | selectors/types |  |  |  |  |

| eventTime | eventSource/name | userIdentity/session/sourceIdentity | source IP/agent | request resource | response/error | readOnly | event ID |
|---|---|---|---|---|---|---|---|
|  |  |  |  |  |  |  |  |

- S3 object-level data events enabled for the relevant bucket/prefix and time:
- All Regions/accounts searched or reason not required:
- One-filter Event history limitation handled:
- Role assumption correlated to subsequent service call:
- Duplicate/retried/eventual-delivery considerations:
- What absence of an event can and cannot prove:

## 7. Timeline and conclusion

| UTC time | Evidence | Interpretation | Confidence/alternative explanation |
|---|---|---|---|
|  |  |  |  |

- Possible access conclusion:
- Simulated decision conclusion:
- Observed-use conclusion:
- Root cause of allow/deny:
- Contradictory or missing evidence:
- Least-privilege remediation:
- Blast radius and rollback:
- Analyzer/simulator/live retest:
- Finding resolution/archive decision and exception expiry:
- Evidence retention and cleanup:
