Enter your keyword

← All Projects  ›  Cloud IAM Governance Playbook & RBAC Matrix
Project 06 - IAM Governance Documentation

Cloud IAM Governance Playbook & RBAC Matrix

18-Account AWS Organizations - Governance Documentation

Designed and documented the complete IAM governance framework for an 18-account AWS Organizations environment - the governance foundation that made technical IAM remediation durable.

8-tier RBAC18 accounts70% exception reductionJIT policyAccess review procedureGovernance documentation
8
RBAC access tiers
18
AWS accounts
70%
Exception requests reduced
0
Standing privileges - 12mo
The Challenge
Problem Statement

The technical IAM remediation documented in Project 04 had failed on its first attempt because it lacked a governance layer. Engineers recreated overpermissive roles within weeks because there was no approved access model to reference, no JIT process that was faster than creating a standing role, and no published rationale for why the controls existed. The governance documentation project was the prerequisite that made the second technical remediation attempt stick.

The Approach
How I Solved It

I designed an eight-tier RBAC model mapping each job function to a defined permission set with documented justification for every boundary. The model covered ReadOnly, Developer, DevOps, Security Analyst, Security Engineer, Database Administrator, Cloud Architect, and Break-Glass Admin tiers - each with permitted services, JIT session requirements, approval authorities, and quarterly review frequencies. I published the full design rationale to engineering teams before implementing any restrictions, explaining the threat scenarios each control was designed to address. I also documented the JIT access request process to make it faster than the previous ad hoc approach.

Frameworks & Standards
NIST SP 800-207 (Zero Trust)
ISO 27001 A.5.15-5.18
CIS AWS Benchmark Level 2
Tools & Platforms
AWS Organizations · SCPs · Permission Boundaries · IAM Identity Center · CyberArk PAM
Category
IAM · Governance Documentation · RBAC
What Was Delivered
Outcomes & Results
Eight-tier RBAC model documented covering all job functions in the AWS environment
Permission Boundary exception requests reduced by 70% after design rationale published - engineers understood the controls and worked within them
JIT access policy documented - all privileged sessions time-bounded with defined session limits per tier
Quarterly access review procedure established - 98% on-time completion rate
Joiner-mover-leaver process documented - automated triggers for access review on role change
Zero standing privileged accounts sustained for 12 consecutive months following implementation
Key Lesson
Security controls that engineers understand and accept are more durable than controls enforced against resistance. Publishing the design rationale - explaining the threat scenario each Permission Boundary was designed to prevent - converted the engineering team from adversaries of the control framework into participants in it. Culture change is faster when the security team explains the why, not just enforces the what.
// Evidence artifact - downloadable
Documented. Verifiable. Downloadable.
This project has a corresponding evidence artifact available in the Evidence Vault.
Download: IAM Governance Playbook & RBAC Matrix