diagnose_iam_exposure
Rank IAM findings to reveal admin sprawl and unusable accounts. Resolves group-inherited policies first, surfacing no-effective-policy, full-admin, broad-data, and disabled-but-privileged risks.
Instructions
[READ][risk=low] Ranked IAM findings: admin sprawl and unusable accounts.
Resolves group-inherited policies first, so a correctly group-managed user is not reported as having no permissions. Findings: NO_EFFECTIVE_POLICY (MinIO denies by default, so the account can do nothing — a broken account that looks identical to a working one in any name-and-status listing), FULL_ADMIN_POLICY, BROAD_DATA_POLICY, DISABLED_BUT_PRIVILEGED. Sorted worst-first with rank.
Args: limit: Maximum findings to return (envelope reports truncation). target: MinIO target name from config; omit for the default.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| target | No |