Daily access should go through IAM Identity Center, not IAM users in member accounts. Ticket work becomes a GitHub issue, then a pull request. Never a direct assignment. Never assign outside git.

The catalog is the source of truth: groups, permission sets, and which accounts they attach to. Standards live in the workflow, not in a wiki Security hopes someone read. Terraform and YAML only. No console clicks.

Issue, not a ticket queue

Someone asks for access the way people actually talk: who needs what, on which account, for how long. The agent resolves that English into accounts, scopes, permission sets, and a least-privilege posture that can survive audit.

A plain-language GitHub issue in. Structured Terraform and YAML out. Human merge before Identity Center.

Identity as code

Named, typed, scoped. The pull request is the only write. Fail, and the agent iterates. Pass, and a human merges sensitive access. Assignment onto accounts happens after that merge, not before.

Ticket work becomes a GitHub issue, then a pull request — never a direct assignment. ~140 permission sets · ~800 assignment rules · 98 policy files. Never assign outside git.

Describe the intent, bind it to a catalog, emit infrastructure as code, and keep a person on the merge. The same loop works for IAM, landing zones, and app-team cloud requests.

Back to workAsk about this workflow