IAMTrail
UnofficialAWS silently updates Managed IAM policies all the time.
We catch every single change.
Full version history and diffs for 1555 AWS Managed IAM Policies, archived since 2019. | A service by zoph.io
Total Policies
1,555
Active AWS Managed Policies
Brand New (v1)
20
New AWS services/features
Deprecated
74
Removed from AWS
Most Active
100
ReadOnlyAccess...
Brand New Policies (v1)
Spot upcoming AWS services early - 20 new policies detected
Get notified when policies change
Daily or weekly email digests with inline diffs. Pick specific policies or track them all.
Endpoint Signals
46 regions, 310 services tracked from botocore
cloudhsmv2ap-southeast-7awslightsailap-southeast-5awsglobalacceleratorap-southeast-6awsPolicy Creation by Year
Number of AWS managed policies first tracked each year
Largest Policy
4054 actions
AWSSupportServiceRolePoli...
AWS Services Tracked
431
IAM service namespaces over time
IAM Actions (literals)
14,107
Distinct action strings in managed policies (no wildcards)
Year-over-Year Velocity
Total policy commits per year - new launches vs. updates
Excludes 4 bulk-reformat day(s) where detection logic changes caused false-positive diffs.
Policy Lifecycle
Current version distribution across all policies
39% of policies (612) are still at v1 - created once and never updated.
Monthly Seasonality
Policy change volume by calendar month across all years
re:Invent Pulse
Policy changes during the Nov 15 - Dec 15 window each year
Recently Updated
AmazonBedrockLimitedAccess
AmazonBedrockMantleFullAccess
AmazonBedrockMantleInferenceAccess
NAPSPropagatorIntegTestManagedPolicy07
AWSWAFConsoleFullAccess
AWSWAFConsoleReadOnlyAccess
AWSWAFFullAccess
AWSWAFReadOnlyAccess
AmazonSageMakerCapacityReservationServiceRolePolicy
Billing
Most Volatile (Trailing 12 Months)
Newest Policies
AmazonBedrockLimitedAccess
AmazonBedrockMantleFullAccess
AmazonBedrockMantleInferenceAccess
NAPSPropagatorIntegTestManagedPolicy07
AWSWAFFullAccess
AWSWAFConsoleReadOnlyAccess
AWSWAFReadOnlyAccess
AWSWAFConsoleFullAccess
AmazonSageMakerCapacityReservationServiceRolePolicy
Billing
Oldest Policies
AWSOpsWorksRegisterCLI
AmazonMachineLearningRoleforRedshiftDataSource
TagGovernancePolicy
AWSLambdaReplicatorInternal
AmazonEverestServicePolicy
AWSB9InternalServicePolicy
AWSBackupAdminPolicy
AWSBackupOperatorPolicy
AWSCloudTrailFullAccess
AWSDataPipelineRole