CloudWise Details Exact AWS IAM Permissions Its Cost Tool Uses and Why
Cloud cost platform CloudWise has published a detailed breakdown of the AWS IAM permissions it requests when users connect their AWS accounts, aiming to clarify what 'read-only' access actually means in practice. The tool deploys a single CloudFormation stack during onboarding, using a custom allow-list policy scoped only to the specific read actions needed for cost scanning, rather than the broad AWS-managed ReadOnlyAccess policy. Every permitted action is a Get, Describe, List, or BatchGet call, with no write, create, delete, or modify verbs included, meaning IAM itself would block any such attempt. A separate, optional remediation role exists for users who want CloudWise to act on identified waste, but it is never deployed during sign-up and includes explicit deny blocks covering identity management, secrets, audit trails, and core infrastructure deletion. The company says it published this transparency post because the word 'read-only' is used loosely across the industry and should not be taken on trust without verification.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in