AWS
Users / IAM
Who has access to your AWS account, whether they have MFA, and a per-user activity report.
IAM is the part of AWS that decides who may do what. This screen lists your IAM users with the three facts that matter most.
The list
| Column | Why it matters |
|---|---|
| Console access | Can this user sign into the AWS web console? |
| MFA | Do they have multi-factor authentication? A console user without MFA is one leaked password away from your whole account |
| Access key last used | When their programmatic key was last used, and for what |
Also shown: the groups they belong to and the policies attached to them.
What to look for
- Console users without MFA. Fix these first. This is also flagged on the Dashboard.
- Access keys never used, or not used for months. An unused key is pure risk with no benefit. Delete it.
- Users you do not recognise. Former staff, contractors, a key created for a tool that was decommissioned.
- Keys that are years old. Rotate them.
Per-user activity report
Select a user and generate an activity report. We read their actions from CloudTrail and produce:
- What they did, grouped and summarised rather than as thousands of raw events;
- an AI-written summary in plain English;
- a PDF export you can send to an auditor or a client.
Use it for:
- Offboarding — what did this contractor actually touch before we remove them?
- Incident review — what did this key do between Tuesday and Thursday?
- Compliance — evidence for an audit.
The report needs cloudtrail:LookupEvents on the key, and only covers the
period CloudTrail retains (90 days by default unless you configured a longer
trail). See Permissions.
What this screen does not do
It is read-only. Creating, deleting and changing IAM users happens in the AWS console. That is deliberate: IAM is the one place where a mistake locks everybody out, and it is not a place for a convenience button.
Good practice
- MFA on every human, no exceptions, starting with root.
- One IAM user per person and per tool — never shared.
- Delete keys that have not been used in 90 days.
- Permissions attached to groups, not individuals.
- A separate, minimal user for DevOps Agent itself. See Connect AWS.
