Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization (RBAC, ABAC, ReBAC), and federated identity. Use when the user mentions 'IAM,' 'identity,' 'access management,' 'least privilege,' 'role design,' 'SSO,' 'SAML,' 'OIDC,' 'OAuth,' 'JIT access,' 'just-in-time access,' 'break-glass,' 'service accounts,' 'RBAC,' 'ABAC,' 'privilege creep,' 'role explosion,' 'identity governance,' 'IAM strategy,' 'identity migration,' 'Okta,' 'Entra ID,' 'Azure AD,' 'Auth0,' 'Cognito,' or needs identity consultant-level guidance.
77
97%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
Low
Low-risk findings worth noting
Cover the identity and access layer end-to-end: audit existing setup, design from scratch, plan migrations, and codify the patterns most teams get wrong. This is the consultant-style skill — not just "what's misconfigured" but "what should this look like."
Three modes — pick the one that matches the engagement:
Cross-references: cloud-audit for the cloud-provider audit (broader than IAM), container-audit for K8s RBAC and ServiceAccounts (orchestration-layer identity).
AWS:
iam:CreateRole + iam:AttachRolePolicy)AdministratorAccess policy attachments — flag every one and justifyAction: "*" or Resource: "*" outside of break-glass rolesPrincipal: { AWS: "*" } is open to the world; should be specific account IDs with optional aws:PrincipalOrgID conditionMetadataOptions.HttpTokens: required on every EC2 launch templateaws accessanalyzer list-findings, aws iam generate-credential-report, aws iam get-account-authorization-detailsGCP:
roles/owner and roles/editor are too broad — replace with custom roles or fine-grained roles/*Adminprojects.serviceAccounts.keys.create) — should be zero; use Workload Identity Federationiam.serviceAccountTokenCreator on themselves = self-impersonation = privilege escalationallUsers / allAuthenticatedUsers bindings on any sensitive resourcegcloud asset analyze-iam-policy, gcloud policy-intelligence query-activity, Recommender APIAzure:
Owner and Contributor role assignments at subscription/management-group scope* actionsaz role assignment list --all, Microsoft Graph auditLogs/signIns, Microsoft Entra recommendationsOkta / Entra ID / Auth0 / Google Workspace:
docs/roles.md or equivalentcan(user, action, resource) function, not scattered if (user.role === "admin") checks throughoutiam:AssumeRole into admin, transitivelyallow or deny should be traceable for incident response.For a new project, design these in this order:
if statement in code is no longer readable.*:Delete* and *:Put* on the log bucket from anything but the logging service.localStorage (XSS-exfiltratable)owasp-audit A07)roles/owner everywhere → custom roles (GCP): use Recommender API to suggest least-privilege replacements; cut over one project at a time# IAM [Audit | Design | Migration] Report
## Scope: [accounts / orgs / IdPs covered]
## Date: [date]
### Executive Summary
[2-3 paragraphs — the IAM posture in plain English, top 3 risks, recommended next 90 days]
### Findings / Recommendations
| ID | Severity | Mode | Category | Issue / Recommendation |
|----|----------|------|----------|------------------------|
### Per-finding detail
[as in owasp-audit — file/resource, description, vulnerable config, remediation, verification]
### Roadmap
[Quarterly milestones — what to do this month, next 90 days, next year]Disposition rule (Fixed / Deferred / Accepted Risk) per owasp-audit.
iam:AttachPolicy, no role creation, no user disablement)c9ade03
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.