About Expertise Work Managed Apps
Business Website Online Store Sales CRM Team Drive Online Academy Newsletter System Booking System Shared Inbox Knowledge Base Short Links Business Manager Photo Gallery Survey Platform Community Forum Project Boards Estate Agency Car Workshop Restaurant Clinic Photography Studio
AWS
Assess & advise Build & migrate Automate & operate Secure & comply Urgent & go-live
Projects
Hosted Monitoring & Dashboards Self-Hosted Observability Stack Bulk Document Data Extraction Email Deliverability Diagnosis & Repair SEO Migration Recovery AWS Security Review VPS Hardening & ModSecurity Cloud Architecture & Resilience Review SSL & Server Configuration Container Security Review DNS & Email Troubleshooting DevOps Deployment & Rollback Review WordPress Hardening Retainer Data Pipeline Rerun Review Metric Reconciliation
Free Tools
Website Health Check Email Domain Health Check DNS Health Check SSL Certificate Checker Redirect Chain Checker Robots.txt Checker XML Sitemap Validator Docker Compose Checker WordPress Security Check AWS IAM / S3 Policy Checker Domain Registration Lookup Uptime Monitoring Trial Downtime Cost Calculator AWS Cost Estimator Cloud Architecture Self-Assessment DevOps Engagement Builder Self-Managed VPS vs Managed AWS
Blog Certifications Hire Me

AWS IAM & Access Cleanup

Who can do what in your account, who has not used it in a year, and what to take away first.

Price and scope

From $299

Typically $299–$649, fixed in writing before anything starts.

2–4 days
Working days, counted from the moment I have access — not from the day you agree.

What moves it up

  • An Identity Center rollout, rather than tidying IAM users in place
  • More than one account, where a role in one trusts a principal in another
  • Federation with an existing identity provider that nobody has documented

Some of this you can check yourself, right now, for free: AWS IAM / S3 Policy Checker →

Who can delete the production databaseSix IAM principals with permission to delete the production database: two current engineers, and four left over — a departed contractor, an access key for a retired script, a widened policy and an unused CI role.nothing removes a permission because it stopped being neededengineer alicein use dailyengineer benin use dailycontractor daveleft in March 2024key AKIA...backupunused 411 daysrole ci-deployunused 260 dayspolicy admin-tempwidened, never undoneproduction databaserds:DeleteDBInstance
AWS IAM & Access Cleanup

What actually goes wrong

Access only ever accumulates. Nothing in AWS removes a permission because it stopped being needed, so what a two-year-old account holds is every decision anyone ever made about it: the contractor whose user was never deleted, the access key created for a script that was replaced in 2024 and still works, the policy that started as a narrow grant and got a wildcard added on a Friday. None of it is an attack. It is just that the answer to "who can delete our production database" is longer than anybody expects, and nobody has read it out loud.

How I find it

  • aws iam get-credential-report — every user, every key, and the date each was last used
  • aws iam generate-service-last-accessed-details — which permissions a role has genuinely exercised
  • aws iam list-policies --scope Local, read for Resource "*" on mutating actions
  • aws organizations list-accounts, where the trust relationships cross an account boundary

What you get

  • A complete inventory of users, roles, groups and keys, with last-used dates against each
  • A named list of what to remove, ordered by risk, with the blast radius of each removal stated
  • Least-privilege replacements for the policies that were widened rather than written
  • MFA enforced on every human principal, with the break-glass path documented and tested
  • A short standing procedure for granting and revoking access, so it does not accumulate again

Questions

Will you lock someone out?

Nothing is removed without your sign-off on a named list, and the break-glass path is tested before the first revocation, not after it. The order is deliberate: I prove you can still get in, then things start coming out.

We use IAM users rather than Identity Center. Is that wrong?

For a small team with one account, IAM users with MFA are workable and I will not push you off them for the sake of it. It stops being workable at the point you have a second account or a third person, because that is when the same human starts existing twice.

Can you do this without seeing our data?

Yes. This work reads IAM, Organizations and access-analyzer metadata. It does not need, and does not request, permission to read the contents of a bucket or a database.

How long before it needs doing again?

The inventory goes stale the first time somebody joins or leaves. That is why the standing procedure is one of the deliverables rather than an upsell — the cleanup is only worth paying for once if what caused it also changes.

AWS Architecture Review

What your account actually looks like, what breaks first, and what it is costing you to keep it that way.

From $299 2–4 days

Want this done?

Tell me what you are running and I will come back with a fixed price and a date. If it turns out you do not need this, I will say that instead.

Prefer to talk? Book a free call ↗  ·  Or hire me on Upwork ↗  ·  Typical reply within one business day.

When I answer

Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.

No 24/7 desk, and I will not pretend otherwise

One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.

Your AWS bill stays yours

You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.

A price that starts with "from" is a starting price

Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.