Identity named as a test account is carrying production access
- Why
- An identity whose name says “test” sits in a production account and can reach resources classified high impact
- What
- aws-role/analytics-test (IAM role)
- Who
- Owner: unknown — no Owner tag, and nobody has assigned one
- Where
- AWS account prod-core (from the connector)
- How
- Its trust policy lets the analytics workload assume it; AWS reports it last used 2 days ago
- Blast radius
- Read on 2 resources classified high impact · effective access, an upper bound
- Recommendation
- Assign an owner, confirm what uses it, scope the inline policy to the reporting resources
- Action
- Assign owner · propose remediation for second-person approval
- Evidence
- IAM snapshot · role last used (AWS-reported) · resource classification record