AWS · Cloud service
AWS IAM Identity Center with OrchestrAI
Catalog exported 2026-09-02
Manage AWS IAM Identity Center from chat: permission sets, managed policy attachment, and account assignments.
OrchestrAI exposes 3 IAM Identity Center operations: 3 create or modify resources and run only after you confirm the plan. Every one of them also carry a step-level approval gate.
What teams use it for
Teams use OrchestrAI to create a permission set for a job function, attach an AWS managed policy such as ReadOnlyAccess to it, and assign it to a user or group for a specific account. All three operations are high risk with confirmation, so each shows who gets access to which account before it runs. There are no list or describe operations, and no way to remove an assignment, delete a permission set, or attach inline or customer managed policies, so auditing and revoking access is done in the console.
Every IAM Identity Center operation, with its risk level
| Operation | What it does | Risk | Step-level approval |
|---|---|---|---|
Attach Managed Policy To Permission Set |
Attach an AWS managed policy to an IAM Identity Center permission set | Modifies existing | Yes |
Create SSO Account Assignment |
Assign a permission set to a user or group for a specific AWS account | Modifies existing | Yes |
Create SSO Permission Set |
Create a permission set in AWS IAM Identity Center (SSO) | Modifies existing | Yes |
Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.
Prompts that work
- Create an IAM Identity Center permission set called ReadOnlyAuditor with a 4 hour session
- Attach the ReadOnlyAccess managed policy to the ReadOnlyAuditor permission set
- Assign the DeveloperAccess permission set to the platform-devs group in account 123456789012
Before anything runs
Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.
Frequently asked questions
- Can OrchestrAI revoke an IAM Identity Center account assignment?
- No, it creates assignments but cannot remove them, so revocation happens in the console.
- Which policies can OrchestrAI attach to an Identity Center permission set?
- AWS managed policies only. Customer managed and inline policies are not covered by the current operation.
- Which IAM Identity Center operations need an extra approval step?
- 3 operations carry a step-level approval gate on top of plan confirmation: Attach Managed Policy To Permission Set, Create SSO Account Assignment, Create SSO Permission Set. None of them is classed destructive.
Other AWS services
Related integrations
Try it on your own account
Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.
Unused credits refunded in your first 14 days.