Season 4: One Company, Two Clouds · Episode 7 of 8
You play: AI Engineering Intern
An audit-log alert fires: the partner analytics role, `partner-analytics`, is reading creator export files it shouldn't be able to see. Its policy was meant to allow one approved prefix of exports; it actually allows the whole export bucket, including raw pipeline output. While you're in the logs, Lydia points at a second problem — someone has been running daily deploys as the AWS root account.
Lydia Roe
Security Engineer
Priya Naidoo
Cloud Architect
The partner role is scoped to the approved export bucket only — read approved allowed, read raw denied, no write — with the policy diff and the two-sided test kept as audit evidence. Reading the log again caught the caption function's role writing where it shouldn't, correctly identified as a Code Nexus-owned IAM misconfiguration under shared responsibility, and root-for-deploys was flagged as a separate finding.