IAMTrail
UnofficialAWS silently updates Managed IAM policies all the time.
We catch every single change.
Full version history and diffs for 1564 AWS Managed IAM Policies, archived since 2019. | A service by zoph.io
Total Policies
1,564
Active AWS Managed Policies
Brand New (v1)
20
New AWS services/features
Deprecated
76
Removed from AWS
Most Active
100
ReadOnlyAccess...
Brand New Policies (v1)
Spot upcoming AWS services early - 20 new policies detected
Get notified when policies change
Daily or weekly email digests with inline diffs. Pick specific policies or track them all.
Endpoint Signals
46 regions, 310 services tracked from botocore
servicecatalogap-southeast-6ca-west-1awsfsxap-southeast-6awsvpc-latticemx-central-1awsPolicy Creation by Year
Number of AWS managed policies first tracked each year
Largest Policy
4169 actions
AWSSupportServiceRolePoli...
AWS Services Tracked
433
IAM service namespaces over time
IAM Actions (literals)
14,335
Distinct action strings in managed policies (no wildcards)
Year-over-Year Velocity
Total policy commits per year - new launches vs. updates
Excludes 4 bulk-reformat day(s) where detection logic changes caused false-positive diffs.
Policy Lifecycle
Current version distribution across all policies
39% of policies (616) are still at v1 - created once and never updated.
Monthly Seasonality
Policy change volume by calendar month across all years
re:Invent Pulse
Policy changes during the Nov 15 - Dec 15 window each year
Recently Updated
AWSECRPullThroughCache_ServiceRolePolicy
AIDevOpsAgentAccessPolicy
AIDevOpsAgentFullAccess
SageMakerStudioUserIAMPermissiveExecutionPolicy
SageMakerStudioAdminIAMDefaultExecutionPolicy
SageMakerStudioAdminIAMPermissiveExecutionPolicy
SageMakerStudioProjectUserRolePolicy
SageMakerStudioUserIAMDefaultExecutionPolicy
AmazonEKSBlockStoragePolicyV2
AWSVPCFlowLogsServiceRolePolicy
Most Volatile (Trailing 12 Months)
Newest Policies
AWSECRPullThroughCache_ServiceRolePolicy
SageMakerStudioUserIAMPermissiveExecutionPolicy
AIDevOpsAgentAccessPolicy
AIDevOpsAgentFullAccess
SageMakerStudioAdminIAMPermissiveExecutionPolicy
SageMakerStudioUserIAMDefaultExecutionPolicy
SageMakerStudioAdminIAMDefaultExecutionPolicy
SageMakerStudioProjectUserRolePolicy
AmazonEKSBlockStoragePolicyV2
AWSVPCFlowLogsServiceRolePolicy
Oldest Policies
AWSOpsWorksRegisterCLI
AmazonMachineLearningRoleforRedshiftDataSource
TagGovernancePolicy
AWSLambdaReplicatorInternal
AmazonEverestServicePolicy
AWSB9InternalServicePolicy
AWSBackupAdminPolicy
AWSBackupOperatorPolicy
AWSCloudTrailFullAccess
AWSDataPipelineRole