Open source · Cloud & Platform

IAM Least Privilege Diff

Compare identity policies and surface privilege changes in human-readable form.

v1.0.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Offline, read-only comparison of two exported AWS IAM identity policy documents. It reports syntactic changes to Allow actions, resources, and simple equality constraints. It never computes effective permissions.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

node bin/iam-least-privilege-diff.mjs --root examples/pass --before before.json --after after.json
node bin/iam-least-privilege-diff.mjs --root examples/fail --before before.json --after after.json
npm run check

Read the result

The CLI emits one JSON report. Exit 0 means pass, 1 means fail, and 2 means incomplete or invalid CLI options. Invalid options or root produce no stdout. Input files are resolved by realpath within --root; escapes, unreadable named files, malformed JSON, duplicate decoded keys (including escaped spellings), and invalid UTF-8 yield incomplete. No files are written.

Where this check stops

Each file is at most 524,288 bytes; each policy at most 1,000 statements; each statement at most 1,000 actions, 1,000 resources, and 100 StringEquals keys/values; JSON depth at most 16; evaluation deadline 5,000 ms with an injectable monotonic clock. At N the boundary is accepted; N+1 yields incomplete. Output order is deterministic UTF-16 code-unit order. The tool does not evaluate groups, attached/inline combinations, permission boundaries, resource policies, service control policies, session policies, explicit-deny effects, principals, condition operators beyond StringEquals, policy variables, wildcard expansion, or live AWS state. Its effectivePermissions field is always not-evaluated; a pass only means no concerning change was found in this supported comparison.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.