**Nothing here is applied to AWS.** They are FILES for the mandatory GPT-4.1 IAM cross-review.
**Cross-review status (2026-06-18): APPROVE, no BLOCKs.** FIXes applied — `aws:SourceAccount`
added to the trust policy; `ec2:DescribeImages` removed from the permission policy (see
`CROSS-REVIEW-PACKET.md` header + `aws-posture-readonly-policy.rationale.md`). The review passing
**unblocked building** `../checkers/aws-posture.sh` (built in this Phase-3 change set). That
checker stays **PROVISIONING-GATED**: it makes NO AWS call until step-ca + the Roles Anywhere
trust anchor + this role are stood up. Provisioning happens only after the review is recorded
(design §7, B3) — and a VM snapshot is taken first per `feedback_ec2_replacement_snapshot`.
Decision (D5): the box stays **read-only** and authenticates to AWS via **Roles Anywhere**
short-lived leaf certs issued by a new internal **step-ca** — **no long-lived AWS key on the
box**.
| File | Purpose |
|---|---|
| `CROSS-REVIEW-PACKET.md` | **Start here.** End-to-end trust model, least-privilege rationale, blast radius, exercised rollback, and the specific items for the reviewer. |