AWS ships IAM Temporary Delegation — 12-hour, wildcard-free, single-endpoint partner access
In a July 27 post, Deepgram details a new IAM capability that lets a software partner request scoped, time-limited access to a customer's resources without long-lived cross-account roles. Access maxes out at 12 hours, is scoped to a single endpoint in a single region in a single account, and the customer reviews fully resolved permissions in their own IAM console with no wildcards at approval time; credentials issue via STS and every delegated call is tagged in CloudTrail with the partner's account ID. Deepgram reports time-to-first-investigation on support tickets dropped from days to minutes, eliminating scheduled screen-shares — a pattern worth copying for anyone shipping self-hosted software on AWS.
↳ Follow the thread