Sharing mechanisms
Plerion detects access through four mechanisms.Covered resource types
Coverage expands over time. The Mechanism column shows how Plerion evaluates each type: from a resource-based policy, from an IAM role’s trust policy, through an AWS Resource Access Manager (RAM) resource share, or from a cross-account permission attribute on the resource.The Amazon ECR registry, AWS Glue Data Catalog, AWS X-Ray resource policy, and Amazon CloudWatch Logs resource policy are account and region-scoped policies. Plerion surfaces each as its own asset rather than as a policy on an individual resource.
What Plerion does not evaluate
- Access with no AWS-side record of the recipient, such as IAM access keys or API keys. There is nothing on the AWS side that identifies who holds them.
- Service Control Policies (SCPs) and Resource Control Policies (RCPs). Plerion evaluates what a resource grants, not the organization-level guardrails that may further restrict it.
Related pages
- Resource access grants overview: How Plerion builds and classifies grants.
- External access: The grants that reach principals outside your organization.
- Access review: Assign grantees, record decisions, and keep an audit history.