1. Support
  2. Integrations
  3. IAM
AWS 105 nodes

IAM

AWS integration · 105 node(s).

00Overview

Manage AWS Identity and Access Management from a flow - create and delete users, groups and roles, attach or detach managed and inline policies, rotate access keys, and set up MFA devices. Read the account password policy, credential report and permissions boundaries, tag any entity, and simulate how a policy would evaluate before you apply it. Because IAM is a global service, one connection covers your whole account regardless of region.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting IAM

  1. In the AWS Console, open IAM → Users (console.aws.amazon.com/iam → Users), select the user Flomation should act as, and under Security credentials choose Create access key to obtain an Access key ID and Secret access key — grant that user only the IAM permissions your flows need.
  2. In the node's Authentication field, pick how Flomation signs in: Access Keys uses the key pair above; Assume Role (cross-account) has Flomation's own AWS principal call sts:AssumeRole on a role you nominate; Managed Role (Credential) reuses an AWS role credential already stored in your workspace.
  3. For Access Keys, fill AWS Access Key and AWS Secret Key, adding Session Token (optional) only when you are using temporary STS credentials.
  4. For Assume Role (cross-account), enter the Role ARN to Assume and, when the target role's trust policy requires one, the matching Assume Role External ID (optional); the role's trust policy must grant Flomation's principal sts:AssumeRole.
  5. Set Region to any valid AWS region (IAM is global, so the value is accepted but not used to scope results), then store your secret key as a Flomation environment secret (e.g. iam_secret) and select it in the node's AWS Secret Key field.
FieldTypeDetails
AuthenticationstringRequiredAccess Keys, Assume Role (cross-account), Managed Role (Credential)
AWS Access KeysecretRequired
AWS Secret KeysecretRequired
Session Token (optional)secret
AWS Role CredentialcredentialRequired
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Add

AWS IAM Add Role To Instance Profile

aws/iam/add_role_to_instance_profile · Action

Add an IAM role to an instance profile.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance Profile NamestringRequiredmy-instance-profile
Role NamestringRequiredmy-role

Returns: tool_result, instance_profile_name, role_name

AWS IAM Add User to Group

aws/iam/add_user_to_group · Action

Add an existing IAM user to an IAM group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequireddevelopers
User NamestringRequiredjane.doe

Returns: tool_result, group_name, user_name

03Attach

AWS IAM Attach Group Policy

aws/iam/attach_group_policy · Action

Attach a managed policy to an IAM group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequiredDevelopers
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy

Returns: tool_result, group_name, policy_arn

AWS IAM Attach Role Policy

aws/iam/attach_role_policy · Action

Attach a managed policy to an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredMyRole
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy

Returns: tool_result, role_name, policy_arn

AWS IAM Attach User Policy

aws/iam/attach_user_policy · Action

Attach a managed policy to an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy

Returns: tool_result, user_name, policy_arn

04Change

AWS IAM Change Password

aws/iam/change_password · Action

Change the calling IAM user's own console password. Both passwords are sensitive.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Current Password (sensitive)secretRequired
New Password (sensitive)secretRequired

Returns: tool_result

05Create

AWS IAM Create Access Key

aws/iam/create_access_key · Action

Create an access key for an IAM user. The secret is shown only once.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe

Returns: tool_result, access_key_id, secret_access_key, status

AWS IAM Create Group

aws/iam/create_group · Action

Create a new IAM group with an optional path.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequireddevelopers
Path (optional)string/division_abc/

Returns: tool_result, group_name, group_id, arn

AWS IAM Create Instance Profile

aws/iam/create_instance_profile · Action

Create an IAM instance profile with optional path and tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance Profile NamestringRequiredmy-instance-profile
Path (optional)string/division_abc/
Tags (optional)key_value_array

Returns: tool_result, instance_profile_name, arn, instance_profile_id

AWS IAM Create Login Profile

aws/iam/create_login_profile · Action

Create a console login profile (password) for an IAM user. Password is sensitive.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Password (sensitive)secretRequired
Require password reset on next sign-in (optional)boolean

Returns: tool_result, user_name, create_date

AWS IAM Create OIDC Provider

aws/iam/create_open_id_connect_provider · Action

Create an IAM OpenID Connect identity provider for SSO federation.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Provider URLstringRequiredhttps://token.actions.githubusercontent.com
Client IDs (comma-separated)stringRequiredsts.amazonaws.com
Thumbprints (comma-separated, optional)string
Tags (optional)key_value_array

Returns: tool_result, open_id_connect_provider_arn

AWS IAM Create Policy

aws/iam/create_policy · Action

Create an IAM managed policy from a JSON document.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy NamestringRequiredMyPolicy
Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}
Description (optional)string
Path (optional)string/division_abc/

Returns: tool_result, policy_name, policy_arn, policy_id

AWS IAM Create Policy Version

aws/iam/create_policy_version · Action

Add a new version to an IAM managed policy, optionally as default.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy
Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}
Set As Default Versionboolean

Returns: tool_result, version_id, is_default

AWS IAM Create Role

aws/iam/create_role · Action

Create a new IAM role with a trust policy, plus optional tags and boundary.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-service-role
Trust Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}
Description (optional)string
Path (optional)string/division_abc/
Max Session Duration (seconds, optional)integer3600
Permissions Boundary ARN (optional)stringarn:aws:iam::<account>:policy/Boundary
Tags (optional)key_value_array

Returns: tool_result, role_name, role_id, arn

AWS IAM Create SAML Provider

aws/iam/create_saml_provider · Action

Create an IAM SAML identity provider for SSO federation from an IdP metadata document.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Provider NamestringRequiredMyCorpIdP
SAML Metadata Document (XML)stringRequired
Tags (optional)key_value_array

Returns: tool_result, saml_provider_arn

AWS IAM Create Service-Linked Role

aws/iam/create_service_linked_role · Action

Create an IAM service-linked role for an AWS service principal.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Service NamestringRequiredelasticbeanstalk.amazonaws.com
Description (optional)string
Custom Suffix (optional)string-1

Returns: tool_result, role_name, arn

AWS IAM Create User

aws/iam/create_user · Action

Create a new IAM user with optional path, permissions boundary and tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Path (optional)string/division_abc/
Permissions Boundary ARN (optional)stringarn:aws:iam::<account>:policy/Boundary
Tags (optional)key_value_array

Returns: tool_result, user_name, user_id, arn

AWS IAM Create Virtual MFA Device

aws/iam/create_virtual_mfa_device · Action

Create a virtual MFA device, returning its seed and QR code.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Virtual MFA Device NamestringRequiredjane.doe
Path (optional)string/division_abc/

Returns: tool_result, serial_number, base32_string_seed, qr_code_png

06Deactivate

AWS IAM Deactivate MFA Device

aws/iam/deactivate_mfa_device · Action

Deactivate an MFA device for an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Serial NumberstringRequiredarn:aws:iam::<account>:mfa/jane.doe

Returns: tool_result, user_name, serial_number

07Delete

AWS IAM Delete Access Key

aws/iam/delete_access_key · Action

Delete an access key belonging to an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Access Key IDstringRequiredAKIA...

Returns: tool_result, access_key_id

AWS IAM Delete Group

aws/iam/delete_group · Action

Delete an IAM group. The group must have no members first.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequireddevelopers

Returns: tool_result, group_name

AWS IAM Delete Group Policy

aws/iam/delete_group_policy · Action

Delete an inline policy from an IAM group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequireddevelopers
Policy NamestringRequiredS3ReadOnly

Returns: tool_result, group_name, policy_name

AWS IAM Delete Instance Profile

aws/iam/delete_instance_profile · Action

Delete an IAM instance profile.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance Profile NamestringRequiredmy-instance-profile

Returns: tool_result, instance_profile_name

AWS IAM Delete Login Profile

aws/iam/delete_login_profile · Action

Delete an IAM user's console login profile, removing password sign-in.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe

Returns: tool_result, user_name

AWS IAM Delete OIDC Provider

aws/iam/delete_open_id_connect_provider · Action

Delete an IAM OpenID Connect identity provider by ARN.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
OIDC Provider ARNstringRequiredarn:aws:iam::<account>:oidc-provider/token.actions.githubusercontent.com

Returns: tool_result

AWS IAM Delete Policy

aws/iam/delete_policy · Action

Delete an IAM managed policy by its ARN.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy

Returns: tool_result, policy_arn

AWS IAM Delete Policy Version

aws/iam/delete_policy_version · Action

Delete a non-default version of an IAM managed policy.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy
Version IDstringRequiredv2

Returns: tool_result

AWS IAM Delete Role

aws/iam/delete_role · Action

Delete an IAM role. Detach policies and instance profiles first.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-service-role

Returns: tool_result, role_name

AWS IAM Delete Role Permissions Boundary

aws/iam/delete_role_permissions_boundary · Action

Remove the permissions boundary from an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredMyRole

Returns: tool_result, role_name

AWS IAM Delete Role Policy

aws/iam/delete_role_policy · Action

Remove an inline policy from an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-role
Policy NamestringRequiredS3ReadOnly

Returns: tool_result, role_name, policy_name

AWS IAM Delete SAML Provider

aws/iam/delete_saml_provider · Action

Delete an IAM SAML identity provider by ARN.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
SAML Provider ARNstringRequiredarn:aws:iam::<account>:saml-provider/MyCorpIdP

Returns: tool_result

AWS IAM Delete Service-Linked Role

aws/iam/delete_service_linked_role · Action

Submit an IAM service-linked role for deletion, returning a task ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredAWSServiceRoleForElasticBeanstalk

Returns: tool_result, deletion_task_id

AWS IAM Delete User

aws/iam/delete_user · Action

Delete an IAM user by name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe

Returns: tool_result, user_name

AWS IAM Delete User Permissions Boundary

aws/iam/delete_user_permissions_boundary · Action

Remove the permissions boundary from an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe

Returns: tool_result, user_name

AWS IAM Delete User Policy

aws/iam/delete_user_policy · Action

Delete an inline policy from an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Policy NamestringRequiredS3ReadOnly

Returns: tool_result, user_name, policy_name

AWS IAM Delete Virtual MFA Device

aws/iam/delete_virtual_mfa_device · Action

Delete a virtual MFA device by its serial number.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Serial NumberstringRequiredarn:aws:iam::<account>:mfa/jane.doe

Returns: tool_result, serial_number

08Detach

AWS IAM Detach Group Policy

aws/iam/detach_group_policy · Action

Detach a managed policy from an IAM group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequiredDevelopers
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy

Returns: tool_result, group_name, policy_arn

AWS IAM Detach Role Policy

aws/iam/detach_role_policy · Action

Detach a managed policy from an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredMyRole
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy

Returns: tool_result, role_name, policy_arn

AWS IAM Detach User Policy

aws/iam/detach_user_policy · Action

Detach a managed policy from an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy

Returns: tool_result, user_name, policy_arn

09Enable

AWS IAM Enable MFA Device

aws/iam/enable_mfa_device · Action

Associate and activate an MFA device for an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Serial NumberstringRequiredarn:aws:iam::<account>:mfa/jane.doe
Authentication Code 1stringRequired123456
Authentication Code 2stringRequired654321

Returns: tool_result, user_name, serial_number

10Generate

AWS IAM Generate Credential Report

aws/iam/generate_credential_report · Action

Start generating the account's IAM credential report (IAM is global; region is ignored).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, state, description

AWS IAM Generate Service Last Accessed Details

aws/iam/generate_service_last_accessed_details · Action

Start a service-last-accessed report for an IAM user, role, group or policy ARN.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Entity ARNstringRequiredarn:aws:iam::<account>:user/jane.doe

Returns: tool_result, job_id

11Get

AWS IAM Get Account Password Policy

aws/iam/get_account_password_policy · Action

Retrieve the password policy for the AWS account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, password_policy

AWS IAM Get Account Summary

aws/iam/get_account_summary · Action

Retrieve IAM entity usage and quota counts for the AWS account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, summary

AWS IAM Get Credential Report

aws/iam/get_credential_report · Action

Retrieve the account's IAM credential report as CSV (IAM is global; region is ignored).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, report_csv, generated_time

AWS IAM Get Group

aws/iam/get_group · Action

Retrieve an IAM group along with the list of its member users.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequireddevelopers

Returns: tool_result, group_name, arn, users, count

AWS IAM Get Group Policy

aws/iam/get_group_policy · Action

Retrieve an inline JSON policy document from an IAM group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequireddevelopers
Policy NamestringRequiredS3ReadOnly

Returns: tool_result, policy_document, group_name, policy_name

AWS IAM Get Instance Profile

aws/iam/get_instance_profile · Action

Retrieve details of an IAM instance profile including its roles.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance Profile NamestringRequiredmy-instance-profile

Returns: tool_result, arn, roles

AWS IAM Get Login Profile

aws/iam/get_login_profile · Action

Retrieve the console login profile for an IAM user (IAM is global; region is ignored).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe

Returns: tool_result, user_name, create_date, password_reset_required

AWS IAM Get OIDC Provider

aws/iam/get_open_id_connect_provider · Action

Retrieve an IAM OpenID Connect identity provider's URL, client IDs and thumbprints.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
OIDC Provider ARNstringRequiredarn:aws:iam::<account>:oidc-provider/token.actions.githubusercontent.com

Returns: tool_result, url, client_ids, thumbprints, create_date

AWS IAM Get Policy

aws/iam/get_policy · Action

Retrieve details of an IAM managed policy by its ARN.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy

Returns: tool_result, policy_name, policy_arn, default_version_id, attachment_count

AWS IAM Get Policy Version

aws/iam/get_policy_version · Action

Retrieve a specific version of an IAM managed policy, including its document.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy
Version IDstringRequiredv2

Returns: tool_result, document, is_default_version

AWS IAM Get Role

aws/iam/get_role · Action

Retrieve an IAM role, including its trust policy document.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-service-role

Returns: tool_result, role_name, role_id, arn, assume_role_policy_document, max_session_duration

AWS IAM Get Role Policy

aws/iam/get_role_policy · Action

Retrieve an inline policy document attached to an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-role
Policy NamestringRequiredS3ReadOnly

Returns: tool_result, policy_document

AWS IAM Get SAML Provider

aws/iam/get_saml_provider · Action

Retrieve an IAM SAML identity provider's metadata document and validity dates.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
SAML Provider ARNstringRequiredarn:aws:iam::<account>:saml-provider/MyCorpIdP

Returns: tool_result, saml_metadata_document, create_date, valid_until

AWS IAM Get Service Last Accessed Details

aws/iam/get_service_last_accessed_details · Action

Retrieve a service-last-accessed report by its job ID (IAM is global; region is ignored).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Job IDstringRequired

Returns: tool_result, job_status, services_last_accessed, count

AWS IAM Get Service-Linked Role Deletion Status

aws/iam/get_service_linked_role_deletion_status · Action

Check the status of a submitted IAM service-linked role deletion task.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Deletion Task IDstringRequiredtask/aws-service-role/...

Returns: tool_result, status, reason

AWS IAM Get User

aws/iam/get_user · Action

Retrieve details about an IAM user (blank name returns the calling user).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User Name (optional)stringBlank = calling user

Returns: tool_result, user_name, user_id, arn, create_date

AWS IAM Get User Policy

aws/iam/get_user_policy · Action

Retrieve an inline JSON policy document from an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Policy NamestringRequiredS3ReadOnly

Returns: tool_result, policy_document, user_name, policy_name

12List

AWS IAM List Access Keys

aws/iam/list_access_keys · Action

List access keys for an IAM user (defaults to the calling user).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User Name (optional)stringjane.doe

Returns: tool_result, access_keys, count

AWS IAM List Attached Group Policies

aws/iam/list_attached_group_policies · Action

List the managed policies attached to an IAM group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequiredDevelopers

Returns: tool_result, attached_policies, count

AWS IAM List Attached Role Policies

aws/iam/list_attached_role_policies · Action

List the managed policies attached to an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredMyRole

Returns: tool_result, attached_policies, count

AWS IAM List Attached User Policies

aws/iam/list_attached_user_policies · Action

List the managed policies attached to an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe

Returns: tool_result, attached_policies, count

AWS IAM List Group Policies

aws/iam/list_group_policies · Action

List the names of inline policies attached to an IAM group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequireddevelopers

Returns: tool_result, policy_names, count

AWS IAM List Groups

aws/iam/list_groups · Action

List IAM groups, optionally filtered by a path prefix.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Path Prefix (optional)string/division_abc/

Returns: tool_result, groups, count

AWS IAM List Instance Profile Tags

aws/iam/list_instance_profile_tags · Action

List the tags attached to an IAM instance profile.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance Profile NamestringRequiredmy-instance-profile

Returns: tool_result, tags, count

AWS IAM List Instance Profiles

aws/iam/list_instance_profiles · Action

List IAM instance profiles, optionally filtered by path prefix.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Path Prefix (optional)string/division_abc/

Returns: tool_result, instance_profiles, count

AWS IAM List MFA Devices

aws/iam/list_mfa_devices · Action

List the MFA devices attached to an IAM user (or the caller).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User Name (optional)stringjane.doe

Returns: tool_result, mfa_devices, count

AWS IAM List OIDC Providers

aws/iam/list_open_id_connect_providers · Action

List all IAM OpenID Connect identity providers defined in the account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, providers, count

AWS IAM List Policies

aws/iam/list_policies · Action

List IAM managed policies, filtered by scope, path and attachment.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Scopestringchoices: All, AWS, Local
Path Prefix (optional)string/division_abc/
Only Attached Policiesboolean

Returns: tool_result, policies, count

AWS IAM List Policy Tags

aws/iam/list_policy_tags · Action

List the tags attached to an IAM customer managed policy.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy ARNstringRequiredarn:aws:iam::123456789012:policy/my-policy

Returns: tool_result, tags, count

AWS IAM List Policy Versions

aws/iam/list_policy_versions · Action

List the versions of an IAM managed policy.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy

Returns: tool_result, versions, count

AWS IAM List Role Policies

aws/iam/list_role_policies · Action

List the inline policy names attached to an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-role

Returns: tool_result, policy_names, count

AWS IAM List Roles

aws/iam/list_roles · Action

List IAM roles, optionally filtered by a path prefix.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Path Prefix (optional)string/division_abc/

Returns: tool_result, roles, count

AWS IAM List SAML Providers

aws/iam/list_saml_providers · Action

List all IAM SAML identity providers defined in the account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, saml_providers, count

AWS IAM List User Policies

aws/iam/list_user_policies · Action

List the names of inline policies attached to an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe

Returns: tool_result, policy_names, count

AWS IAM List User Tags

aws/iam/list_user_tags · Action

List the tags attached to an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe

Returns: tool_result, tags, count

AWS IAM List Users

aws/iam/list_users · Action

List IAM users, optionally filtered by a path prefix.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Path Prefix (optional)string/division_abc/

Returns: tool_result, users, count

13Put

AWS IAM Put Group Policy

aws/iam/put_group_policy · Action

Add or update an inline JSON policy on an IAM group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequireddevelopers
Policy NamestringRequiredS3ReadOnly
Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}

Returns: tool_result, group_name, policy_name

AWS IAM Put Role Permissions Boundary

aws/iam/put_role_permissions_boundary · Action

Set the permissions boundary policy on an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredMyRole
Permissions Boundary ARNstringRequiredarn:aws:iam::<account>:policy/Boundary

Returns: tool_result, role_name, permissions_boundary

AWS IAM Put Role Policy

aws/iam/put_role_policy · Action

Add or update an inline JSON policy on an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-role
Policy NamestringRequiredS3ReadOnly
Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}

Returns: tool_result, role_name, policy_name

AWS IAM Put User Permissions Boundary

aws/iam/put_user_permissions_boundary · Action

Set the permissions boundary policy on an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Permissions Boundary ARNstringRequiredarn:aws:iam::<account>:policy/Boundary

Returns: tool_result, user_name, permissions_boundary

AWS IAM Put User Policy

aws/iam/put_user_policy · Action

Add or update an inline JSON policy on an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Policy NamestringRequiredS3ReadOnly
Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}

Returns: tool_result, user_name, policy_name

14Remove

AWS IAM Remove Role From Instance Profile

aws/iam/remove_role_from_instance_profile · Action

Remove an IAM role from an instance profile.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance Profile NamestringRequiredmy-instance-profile
Role NamestringRequiredmy-role

Returns: tool_result, instance_profile_name, role_name

AWS IAM Remove User from Group

aws/iam/remove_user_from_group · Action

Remove an IAM user from an IAM group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequireddevelopers
User NamestringRequiredjane.doe

Returns: tool_result, group_name, user_name

15Resync

AWS IAM Resync MFA Device

aws/iam/resync_mfa_device · Action

Resynchronise an IAM user's MFA device with two auth codes.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Serial NumberstringRequiredarn:aws:iam::<account>:mfa/jane.doe
Authentication Code 1stringRequired123456
Authentication Code 2stringRequired654321

Returns: tool_result, user_name, serial_number

16Set

AWS IAM Set Default Policy Version

aws/iam/set_default_policy_version · Action

Set which version of an IAM managed policy is the active default.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy ARNstringRequiredarn:aws:iam::<account>:policy/MyPolicy
Version IDstringRequiredv2

Returns: tool_result

17Simulate

AWS IAM Simulate Custom Policy

aws/iam/simulate_custom_policy · Action

Simulate how supplied IAM policy documents evaluate against actions and resources.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy Documents (JSON array)stringRequired["{\"Version\":\"2012-10-17\",\"Statement\":[...]}"]
Action Names (comma-separated)stringRequireds3:GetObject, s3:PutObject
Resource ARNs (comma-separated, optional)stringarn:aws:s3:::my-bucket/*

Returns: tool_result, evaluation_results, count

AWS IAM Simulate Principal Policy

aws/iam/simulate_principal_policy · Action

Simulate how a principal's policies evaluate against actions and resources.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy Source ARNstringRequiredarn:aws:iam::<account>:user/jane.doe
Action Names (comma-separated)stringRequireds3:GetObject, s3:PutObject
Resource ARNs (comma-separated, optional)stringarn:aws:s3:::my-bucket/*

Returns: tool_result, evaluation_results, count

18Tag

AWS IAM Tag Instance Profile

aws/iam/tag_instance_profile · Action

Add or update tags on an IAM instance profile.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance Profile NamestringRequiredmy-instance-profile
Tagskey_value_arrayRequired

Returns: tool_result, instance_profile_name

AWS IAM Tag Policy

aws/iam/tag_policy · Action

Add or update tags on an IAM customer managed policy.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy ARNstringRequiredarn:aws:iam::123456789012:policy/my-policy
Tagskey_value_arrayRequired

Returns: tool_result, policy_arn

AWS IAM Tag Role

aws/iam/tag_role · Action

Add or update tags on an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-service-role
Tagskey_value_arrayRequired

Returns: tool_result, role_name

AWS IAM Tag User

aws/iam/tag_user · Action

Add or update tags on an IAM user.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Tagskey_value_arrayRequired

Returns: tool_result, user_name

19Untag

AWS IAM Untag Instance Profile

aws/iam/untag_instance_profile · Action

Remove one or more tags from an IAM instance profile by tag key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance Profile NamestringRequiredmy-instance-profile
Tag Keys (comma-separated)stringRequiredEnvironment,Owner

Returns: tool_result, instance_profile_name

AWS IAM Untag Policy

aws/iam/untag_policy · Action

Remove one or more tags from an IAM policy by tag key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Policy ARNstringRequiredarn:aws:iam::123456789012:policy/my-policy
Tag Keys (comma-separated)stringRequiredEnvironment,Owner

Returns: tool_result, policy_arn

AWS IAM Untag Role

aws/iam/untag_role · Action

Remove one or more tags from an IAM role by tag key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-service-role
Tag Keys (comma-separated)stringRequiredEnvironment,Owner

Returns: tool_result, role_name

AWS IAM Untag User

aws/iam/untag_user · Action

Remove one or more tags from an IAM user by tag key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Tag Keys (comma-separated)stringRequiredEnvironment,Owner

Returns: tool_result, user_name

20Update

AWS IAM Update Access Key

aws/iam/update_access_key · Action

Activate or deactivate an IAM user's access key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
Access Key IDstringRequiredAKIA...
StatusstringRequiredchoices: Active, Inactive

Returns: tool_result, access_key_id, status

AWS IAM Update Account Password Policy

aws/iam/update_account_password_policy · Action

Update the password policy for the AWS account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Minimum Password Length (optional)integer8
Require Symbolsboolean
Require Numbersboolean
Require Uppercase Charactersboolean
Require Lowercase Charactersboolean
Allow Users To Change Passwordboolean
Max Password Age (days, optional)integer90
Password Reuse Prevention (optional)integer5

Returns: tool_result

AWS IAM Update Assume Role Policy

aws/iam/update_assume_role_policy · Action

Replace the trust (assume role) policy document of an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-service-role
Trust Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}

Returns: tool_result, role_name

AWS IAM Update Group

aws/iam/update_group · Action

Rename an IAM group or change its path.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequireddevelopers
New Group Name (optional)stringengineers
New Path (optional)string/division_abc/

Returns: tool_result

AWS IAM Update Login Profile

aws/iam/update_login_profile · Action

Update an IAM user's console password or reset flag. Password is sensitive.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
New Password (sensitive, optional)secret
Require password reset on next sign-in (optional)boolean

Returns: tool_result, user_name

AWS IAM Update Role

aws/iam/update_role · Action

Update an IAM role's description and/or maximum session duration.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Role NamestringRequiredmy-service-role
Description (optional)string
Max Session Duration (seconds, optional)integer3600

Returns: tool_result, role_name

AWS IAM Update SAML Provider

aws/iam/update_saml_provider · Action

Update an IAM SAML identity provider with a new IdP metadata document.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
SAML Provider ARNstringRequiredarn:aws:iam::<account>:saml-provider/MyCorpIdP
SAML Metadata Document (XML)stringRequired

Returns: tool_result, saml_provider_arn

AWS IAM Update User

aws/iam/update_user · Action

Rename an IAM user or change its path.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
User NamestringRequiredjane.doe
New User Name (optional)stringjane.smith
New Path (optional)string/division_abc/

Returns: tool_result, user_name

21Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • When you create an access key, the secret access key is shown only once at creation and cannot be retrieved afterwards, so capture and store it securely at that moment.
  • IAM is eventually consistent, so newly created users, keys, and policy changes may take a short time to propagate before they take effect across AWS.
  • The credential report and the service-last-accessed report are produced asynchronously: requesting a report and retrieving it are separate actions with no built-in polling, so a report may need to be requested more than once until it is ready.
  • A region must be supplied on every action, but because IAM is a global service the region value is ignored.
  • Some resources must have their dependencies removed before they can be deleted — for example, a role must have its attached or inline policies and instance profiles detached first, and a group must have no members.