Ross ROSS = Recommend OSS · open-source software intelligence for agents

salesforce/policy_sentry

IAM Least Privilege Policy Generator observed · 2026-08-28

github.com/salesforce/policy_sentry · homepage · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

88/100

  • Activity 98
  • Release rhythm 67
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 52
  • age_days: 2540
  • days_rel: 142
  • days_push: 17
  • n_releases_24m: 6

Full methodology

Adoption not part of the score

2166 stars · 156 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Policy Sentry is a Python CLI tool and library that generates least-privilege AWS IAM policies. It automates writing security-conscious IAM policies by looking up AWS actions, resources, and condition keys instead of hand-crafting them.

Use cases

  • generate least privilege IAM policies for AWS roles
  • avoid writing AWS IAM policies by hand
  • scope IAM policies to specific resource ARNs
  • query the AWS IAM actions, resources, and condition keys database
  • audit and tighten overly permissive IAM policies
  • integrate IAM policy generation into Terraform or CI pipelines

When to choose

  • you write AWS IAM policies for users, roles, or infrastructure as code
  • your team wants to enforce least-privilege access on AWS
  • you need programmatic or CLI-based IAM policy generation

When to avoid

  • you work with clouds other than AWS
  • you need general cloud security posture management rather than IAM policy authoring

Facets

cli-tool · maturity stable

security developer-tools cli infrastructure-as-code security cloud-computing developer-tools cli python cross-platform aws iam least-privilege iam-policy cloud-security policy-generation devops docker

2 sources

Member repositories

RepositoryRoleHealth v2
salesforce/policy_sentrymain88

For agents

markdown · JSON · MCP: product_card(name="salesforce/policy_sentry")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem