security//IAM
IAM (identity and access management) is the system that defines who or what an identity is, how it proves it, and which actions on which resources it may perform, and in a cloud account it is the control that decides whether a given person, service or script can read a bucket, start a GPU or delete a database. Every request to a cloud provider's API is checked against IAM before anything happens.
IAM (identity and access management) is the system that defines who or what an identity is, how it proves it, and which actions on which resources it may perform, and in a cloud account it is the control that decides whether a given person, service or script can read a bucket, start a GPU or delete a database. Every request to a cloud provider's API is checked against IAM before anything happens.
It joins two questions that are easy to confuse. Authentication asks who are you, answered by a password and second factor for a person, or by a key, token or certificate for a machine (authentication, API key). Authorization asks what may you do, answered by policies attached to identities or roles: this role may read these logs, that service account may write to this one queue and nothing else. A system can authenticate perfectly and still authorize far too much.
A credential made for reading statistics must never be able to move a machine.
The worst incidents come less from broken encryption than from identities holding more permission than their job needs: a dashboard's token that can also change setpoints, a build script that can delete production. IAM's main job is to keep each identity's power down to its task (minimum privilege), so a stolen or misused credential does bounded damage.
Machines outnumber people. Services, pipelines, AI agents and devices each need their own identity (a service account), with short-lived credentials issued automatically rather than long-lived keys pasted into configuration files, where they leak.
Roles scale better than individual grants. Permissions are given to roles (operator, viewer, deployer) and people or services are assigned roles, which keeps hundreds of identities reviewable; role-based access control is the usual name.
IAM is the core of a Zero Trust design, which evaluates every request against identity and policy, and its logs are what a SIEM reads to spot an identity behaving out of character. For AI agents with tools it is the line between an assistant and an incident (agent containment).