Home icon

IAM Policy Autopilot: An open-source tool that brings IAM policy expertise to builders and AI coding assistants

Security Blog



This article announces IAM Policy Autopilot, an open-source tool that automatically generates AWS IAM policies by analyzing application code, available as CLI and MCP server.

  • Analyzes Python, Go, and TypeScript code to generate identity-based IAM policies from AWS SDK calls
  • Understands cross-service dependencies, automatically including KMS permissions for S3 encryption scenarios
  • Integrates with AI coding assistants (Claude, Cursor, Cline, Amazon Q) via Model Context Protocol
  • Detects Access Denied errors during testing and proposes targeted policy fixes
  • Available as standalone CLI tool or MCP server for different development workflows
  • Generates baseline policies prioritizing functionality; developers refine for least-privilege access
  • Currently limited to identity-based policies; doesn't create resource-based policies

IAM Policy Autopilot accelerates AWS development by automating policy creation, reducing permission troubleshooting, and enabling developers to focus on application code rather than IAM expertise.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Dec 1
2025
Simplify IAM policy creation with IAM Policy Autopilot, a new open source MCP server for builders
Dec 1
2025
AWS announces IAM Policy Autopilot to help builders generate IAM policies from code
Jan 20
2026
Using generative AI for proactive IaC code generation that’s compliant with service control policies using Amazon Bedrock
May 8
2026
IAM Policy Autopilot adds Java support and Terraform-aware policy generation

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.