Gate 1
Account and organization
Record account type, organization and OU, Role Manager state, account-property owner, SCPs, approved consoles, and whether a sandbox or production boundary applies.
Template-to-production authority check
Describe the AWS account, organization, service, caller, role template, resource, evidence, and production plan. Generate a checklist without treating automatic role creation as automatic least privilege.
Gate 1
Record account type, organization and OU, Role Manager state, account-property owner, SCPs, approved consoles, and whether a sandbox or production boundary applies.
Gate 2
Name the calling principal, exact template ARN and version, replacement parameters, required underlying IAM actions, trust policy, and intended create-or-reuse outcome.
Gate 3
Map the resulting role to one accountable resource and owner, retain the AcquireRole CloudTrail event, inspect materialized policies, and test both allowed and denied paths.
Gate 4
Define activity coverage, rare paths, Access Analyzer review, policy canary, rollback, drift monitoring, template-management exit, and role retirement before production.
The supported console, caller, template, SCP, CloudTrail, owner, cost boundary, and expiry are known; the role remains a development starting point.
The materialized role is inventoried, representative and denial tests pass, rare paths are planned, and a reviewed scope-down candidate has a rollback.
The role is broad, shared without ownership, missing template evidence, blocked from audit, or promoted without least-privilege, canary, and recovery proof.
Retrieve the exact template version, run one approved and one intentionally denied acquisition path, reconcile the CloudTrail event to the role and service resource, inspect the materialized trust and permissions, exercise representative and rare workload paths, canary a narrower policy, and prove rollback. Do not test broad permissions against production data.
Official facts checked August 19, 2026 against AWS IAM documentation and the AWS Security Blog. Recheck account defaults, supported services, exact template versions, SCPs, analyzer behavior, and organization policy before use.