Understand the concept
IAM defines who or what may perform actions on resources. A role can provide temporary credentials to an application, avoiding long-lived keys in code. Least privilege requires actions, resources, and conditions matching actual work. Administrator access is not a generic application requirement.
Apply and decide
Protect the root user and restrict usage to tasks requiring it. For people, favor federation and strong authentication. Encryption in transit and at rest address different risks; key and permission management still matter. A provider compliance report does not prove your configuration meets all requirements.
Workplace application
For a reporting job, identify exact actions and objects it needs to read. Compare a limited role with a shared administrative credential. Confirm how the application receives credentials and how permissions are removed when the job is retired. A private subnet may limit paths but does not prove correct authorization. During handover, record who reviews access and where to obtain evidence of applied configuration.
A job needs to read one specific bucket. A role with that access is more appropriate than distributing an administrator key.
Common pitfalls
Confusing roles with least privilege; a role can also have excessive access.
Related topics: Regions, zones, and resilience · Choose compute and data services
Give the right identity necessary access with controlled duration.
Reference: IAM security best practices · CLF-C02