AWS

Users / IAM

Who has access to your AWS account, whether they have MFA, and a per-user activity report.

IAM is the part of AWS that decides who may do what. This screen lists your IAM users with the three facts that matter most.

The list

ColumnWhy it matters
Console accessCan this user sign into the AWS web console?
MFADo they have multi-factor authentication? A console user without MFA is one leaked password away from your whole account
Access key last usedWhen their programmatic key was last used, and for what

Also shown: the groups they belong to and the policies attached to them.

What to look for

  • Console users without MFA. Fix these first. This is also flagged on the Dashboard.
  • Access keys never used, or not used for months. An unused key is pure risk with no benefit. Delete it.
  • Users you do not recognise. Former staff, contractors, a key created for a tool that was decommissioned.
  • Keys that are years old. Rotate them.

Per-user activity report

Select a user and generate an activity report. We read their actions from CloudTrail and produce:

  • What they did, grouped and summarised rather than as thousands of raw events;
  • an AI-written summary in plain English;
  • a PDF export you can send to an auditor or a client.

Use it for:

  • Offboarding — what did this contractor actually touch before we remove them?
  • Incident review — what did this key do between Tuesday and Thursday?
  • Compliance — evidence for an audit.

The report needs cloudtrail:LookupEvents on the key, and only covers the period CloudTrail retains (90 days by default unless you configured a longer trail). See Permissions.

What this screen does not do

It is read-only. Creating, deleting and changing IAM users happens in the AWS console. That is deliberate: IAM is the one place where a mistake locks everybody out, and it is not a place for a convenience button.

Good practice

  • MFA on every human, no exceptions, starting with root.
  • One IAM user per person and per tool — never shared.
  • Delete keys that have not been used in 90 days.
  • Permissions attached to groups, not individuals.
  • A separate, minimal user for DevOps Agent itself. See Connect AWS.