The boundary held. Everything forbidden was refused; everything needed was permitted.
| probe | expected | result | what AWS said |
| read the proof bucket | deny | denied | An error occurred (AccessDenied) when calling the ListObjectsV2 operation: User: arn:aws:sts::339163283707:assumed-role/enclavize-apply/i-079ddfe2d5d29e9da is |
| write the dashboard bucket | deny | denied | An error occurred (AccessDenied) when calling the PutObject operation: User: arn:aws:sts::339163283707:assumed-role/enclavize-apply/i-079ddfe2d5d29e9da is not |
| delete the admin role | deny | denied | An error occurred (AccessDenied) when calling the DeleteRole operation: User: arn:aws:sts::339163283707:assumed-role/enclavize-apply/i-079ddfe2d5d29e9da is not |
| unlock the console | deny | denied | aws: [ERROR]: argument operation: Found invalid choice 'delete-console-authorization-configuration' usage: aws [options] <command> <subcommand> [<subcommand> |
| list registered domains | deny | denied | An error occurred (AccessDeniedException) when calling the ListDomains operation: User: arn:aws:sts::339163283707:assumed-role/enclavize-apply/i-079ddfe2d5d29e |
| rewrite proof.sophi.chat | deny | denied | An error occurred (AccessDenied) when calling the ChangeResourceRecordSets operation: User: arn:aws:sts::339163283707:assumed-role/enclavize-apply/i-079ddfe2d5 |
| create an unbounded role | deny | denied | An error occurred (AccessDenied) when calling the CreateRole operation: User: arn:aws:sts::339163283707:assumed-role/enclavize-apply/i-079ddfe2d5d29e9da is not |
| create my own bucket | allow | allowed | { "Location": "/evize-app-339163283707", "BucketArn": "arn:aws:s3:::evize-app-339163283707" } |
| describe my own instances | allow | allowed | { "Reservations": [ { "ReservationId": "r-0b13fc38ab2b473ea", "OwnerId": "339163283707", "Groups": [], |
| use step functions for myself | allow | allowed | { "stateMachines": [ { "stateMachineArn": "arn:aws:states:us-east-1:339163283707:stateMachine:enclavize-apply", "name": "enc |