From 7733c6c6d1ba0cfc3423cff4d0b2f3faf319b73a Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Mon, 28 Sep 2026 16:14:56 +0000 Subject: [PATCH] docs(iam): point the policy-check role at its CI job (PLAT-234) The Access Analyzer checks live in seahaven-org-baseline pull request 160. This role is only the principal that job assumes. Co-authored-by: Adam Moussa --- oidc-deploy-roles.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 432e9e8..b096864 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1381,6 +1381,12 @@ Resources: + # PLAT-234 principal only. The checks are seahaven-org-baseline pull request + # 160: .github/workflows/ci.yaml job iam-policy-check and + # scripts/check_iam_policies.py. That job assumes this role. It asserts + # StringEquals on the bootstrap trust templates, no lambda write on the + # plan template, then ValidatePolicy and CheckNoNewAccess when this role + # can be assumed. SeahavenOrgBaselinePolicyCheckRole: Type: AWS::IAM::Role Properties: