Sign in to Permeon
See what IAM access each pull request adds or removes, how risky it is, and how to narrow it before merge.
You'll see the repositories you can access that have the Permeon GitHub App installed.
- AWS IAM permission changes in policy JSON and supported Terraform, reported on the pull requests that make them
- Deterministic rules for privilege escalation, wildcards and sensitive actions
- Concrete remediation guidance for each finding
New here? Three steps
- Install the Permeon GitHub App on repositories with IAM policies or Terraform.
- Sign in with the same GitHub account.
- Open a pull request that changes a supported IAM file.
Supported today
- AWS IAM policy documents in
.jsonfiles - Terraform
aws_iam_policy,aws_iam_role_policy,aws_iam_user_policyandaws_iam_group_policywithjsonencodeor heredoc JSON policies - Pull requests in repositories where the Permeon GitHub App is installed. Pull requests that don't change these files get no comment.
Permeon reads repository contents and writes one comment per pull request. It never changes code and never calls AWS.