Review Cloud Identity Policy
review_cloud_identity_policyAnalyze raw AWS IAM, Azure RBAC, or GCP IAM policy JSON against provider-specific identity security packs. Review cross-cloud policy risks locally without calling cloud APIs or changing permissions.
Instructions
Apply deterministic provider-specific identity policy packs to raw AWS IAM, Azure RBAC or GCP IAM policy documents. Use this for cross-cloud identity security analysis; use review_iam_policy when assessing AWS IAM from mixed structured facts or policy JSON. It analyzes supplied policy JSON only and does not call cloud APIs or change permissions.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| provider | Yes | Cloud provider whose identity policy syntax and policy pack should be applied. | |
| policyJson | Yes | Raw provider policy document in JSON form; AWS IAM, Azure role definition/assignment data, or GCP IAM policy. | |
| policyName | Yes | Name or identifier of the identity policy being reviewed. | |
| environment | No | Optional deployment environment used to contextualize policy risk; defaults are handled by the policy pack. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| facts | Yes | ||
| findings | Yes | ||
| provider | Yes | ||
| riskLevel | Yes | ||
| riskScore | Yes | ||
| policyName | Yes | ||
| policyPack | Yes | ||
| environment | Yes | ||
| findingCount | Yes | ||
| highFindings | Yes | ||
| mediumFindings | Yes | ||
| recommendedGate | Yes | ||
| criticalFindings | Yes | ||
| assessmentConfidence | Yes |