Previously known as MAMIP (Monitor AWS Managed IAM Policies).
Track every change to AWS Managed IAM Policies with full version history and validation.
Explore AWS Managed IAM Policies through a searchable web interface at iamtrail.com:
- A homepage that leads with this week's changes that matter and the newest AWS services spotted, with the charts on /stats
- Search and filter across 1,465+ managed policies, or search an IAM action to find every policy that grants it, by name or through a wildcard such as
s3:Get* - Full version history with git diffs for every policy
- Syntax-highlighted JSON policy viewer, rendered at build time so every policy and IAM action page is readable by search engines and link previews
- New (v1) policy tracking to spot new AWS services
- Security findings - a critical, high or medium risk level for every managed policy that grants admin access, a documented pathfinding.cloud privilege escalation path, identity administration, secret or data reads, the power to disable monitoring, or a whole-service wildcard. Each finding says whether the grant is unrestricted or scoped to named resources or a condition, and how to use the policy with caution. Paste
aws iam list-attached-role-policiesoutput to check your own role, follow the 90-day timeline of policies that became riskier, or script against/api/v1/risk.json. Access Analyzer security warnings feed the same assessment - Known AWS Account lookup - identify who owns one or a whole list of AWS account IDs, powered by the fwdcloudsec/known_aws_accounts community dataset
Subscribe to policy changes:
-
Email Digest (recommended): Subscribe on iamtrail.com - instant, daily or weekly emails with inline diffs, no account required. Paste the output of the command below to follow only the AWS managed policies attached in your account; it is parsed in your browser and only the matched names are stored:
aws iam list-policies --scope AWS --only-attached --query 'Policies[].Arn' --output text -
Slack: once your email subscription is confirmed, connect a Slack incoming webhook from the manage page and every notification is also posted to that channel. A webhook Slack revokes is detached automatically and you are emailed.
-
Bluesky (unified feed - IAM policies, endpoints, GuardDuty): @iamtrail.bsky.social
-
RSS Feeds (all feeds):
- All Changes - everything in one feed
- IAM Policy Changes - policy updates, new policies, deprecations
- Endpoint Changes - new regions, services, and expansions from botocore
- GuardDuty Announcements - new findings, features, and region launches
See docs/notifications-and-social.md for SSM parameters, Bluesky queue, and GitHub Actions IAM.
All policies are stored as JSON in this repository and updated automatically every hour, every day.
| Path | Description |
|---|---|
policies/ |
1,465+ current AWS Managed IAM Policies |
findings/ |
Access Analyzer validation results |
DEPRECATED.json |
Historical record of 73+ deprecated policies |
The whole archive is also published as versioned JSON at https://iamtrail.com/api/v1. No key, no sign-up, no rate limit - these are static files on the same CloudFront distribution that serves the site. Full documentation at iamtrail.com/api.
| Resource | Description |
|---|---|
/api/v1/index.json |
Service index: contract version, counts, and the URL of every other resource |
/api/v1/policies.json |
Every tracked policy with its ARN, current version and dates |
/api/v1/policies/{policyName}.json |
One policy: current IAM document plus full version history with per-version action deltas |
/api/v1/changes.json |
Recent changes, each naming the actions added and removed |
/api/v1/actions.json |
Every literal IAM action mapped to the policies that allow, deny or NotAction it, plus wildcardGrants: every Allow wildcard by service prefix and pattern |
/api/v1/discoveries.json |
Actions and service prefixes seen for the first time anywhere in the archive |
# What changed in the last day
curl -s https://iamtrail.com/api/v1/changes.json \
| jq -r '.changes[]
| select(.date > (now - 86400 | todate))
| "\(.policyName) \(.versionId): \(.summary)"'Fields are added, never removed or repurposed, within a version. A breaking change means a new path under /api/v2/.
An automated workflow runs every hour, every day:
- Fetch all AWS Managed IAM Policies via the AWS API
- Detect new, updated, or deprecated policies
- Validate each policy with AWS Access Analyzer
- Commit changes to git (one commit per policy)
- Notify via Bluesky, Telegram, RSS, email digests, subscribers' Slack channels, and an invite-only Discord webhook (SSM only, not linked on the site)
The website also rebuilds daily on its own schedule, so the homepage's seven-day window keeps moving through a week with no policy change.
Inspired by Scott Piper's original aws_managed_policies repository. Thank you, Scott, for pioneering this.
GNU General Public License v3.0 - see LICENSE for details.
