OrchestrAI Live

AWS · Cloud service

AWS Identity and Access Management with OrchestrAI

Catalog exported 2026-09-02

Manage AWS IAM from chat: roles, policies, users, and instance profiles, with confirmation on every change.

OrchestrAI exposes 7 IAM operations: 6 create or modify resources and run only after you confirm the plan, and 1 is destructive and requires a typed risk phrase. Every one of them also carry a step-level approval gate.

7operations
0low risk
6create or modify
1destructive
7step-level approval

What teams use it for

Teams use OrchestrAI to create a role with a trust policy for a service, write a custom policy, attach a managed policy to a role, create an instance profile and add the role to it for EC2, or add a new IAM user. Every IAM operation is high risk with confirmation, and deleting a role is critical and requires a typed risk phrase. There are no read or list operations for IAM, and no detach, delete user, or delete policy, so auditing existing permissions is done elsewhere.

Every IAM operation, with its risk level

AWS Identity and Access Management operations available through OrchestrAI
Operation What it does Risk Step-level approval
Attach Policy to Role Attach a managed policy to an IAM role Modifies existing Yes
Attach Role To Instance Profile Attach an IAM role to an instance profile Modifies existing Yes
Create IAM Instance Profile Create an IAM instance profile for EC2 role attachment Modifies existing Yes
Create IAM Policy Create a custom IAM policy Modifies existing Yes
Create IAM Role Create an IAM role with trust policy Modifies existing Yes
Create IAM User Create a new IAM user Modifies existing Yes
Delete IAM Role Delete an IAM role Destructive Yes

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

Prompts that work

  • Create an IAM role ecs-task-role trusted by ecs-tasks.amazonaws.com and attach AmazonS3ReadOnlyAccess
  • Create a custom policy that allows s3:GetObject on the reports-bucket and attach it to the reporting-lambda role
  • Create an instance profile for the web-server role

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Can OrchestrAI list IAM roles or policies?
No, IAM coverage is write-only: create role, policy, user, instance profile, attach policy, and delete role. Reviewing existing permissions is done in the console or IAM Access Analyzer.
Why does OrchestrAI treat every IAM change as high risk?
IAM changes alter who can do what in the account. Each one shows its plan and waits for explicit confirmation; role deletion also requires the typed risk phrase.
Which IAM operations need an extra approval step?
7 operations carry a step-level approval gate on top of plan confirmation: Attach Role To Instance Profile, Attach Policy to Role, Create IAM Instance Profile, Create IAM Policy, Create IAM Role, Create IAM User, Delete IAM Role. One of these is classed destructive and cannot run without a typed risk phrase.

Other AWS services

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.