๐Ÿ›๏ธ
๐Ÿ”‘
๐Ÿ“‹
๐Ÿ‘ฅ
An AWS IAM Story

The Stalls of
Makola Market

Auntie Ama owns a busy fabric shop in Makola Market. Her workers, helpers, and visiting traders all need different levels of access. Some can sell. Some can't touch the cash box. Some only borrow her apron for one task. That's not chaos โ€” that's identity and access management.

Visit the shop
SCROLL TO ENTER
Chapter 1 ยท The Shop

One shop, one owner

Auntie Ama runs a busy fabric stall. She owns it. She has the master key. She decides who walks in, who can touch the cash box, who can restock the shelves, and who is allowed nowhere near the inventory ledger.

Without rules, the shop would be chaos โ€” anyone could grab anything. With rules, every person has a clear role: cashier, restocker, cleaner, supplier.

That's exactly what AWS IAM does for your account. One owner. Many people. Different permissions for each.

IAM โ€” Identity & Access Management
AMA'S FABRIC STALL CASH BOX AUNTIE AMA (owner) ROOT KEY One AWS account, one root user, many identities
Chapter 2 ยท The Workers

Each worker has their own ID badge

Auntie Ama hires three workers: Kwesi the cashier, Adwoa the restocker, and Kofi the cleaner. Each one gets a personalized name badge and a key to the side door. The keys are NOT the same as Ama's master key.

Kwesi's badge says "Kwesi ยท Cashier." Adwoa's badge says "Adwoa ยท Restocker." Each badge is unique to its owner. If Kofi loses his badge, only Kofi's access gets revoked โ€” not everyone's.

That's exactly what an IAM UserAn IAM User is a permanent identity within your AWS account that represents a single person or service. Each user has unique credentials. is in AWS. One user = one human (or one application). Each has their own login, their own credentials, their own identity.

IAM Users โ€” One Per Person
Three workers ยท Three badges KWESI Kwesi Cashier ADWOA Adwoa Restocker KOFI Kofi Cleaner Each user ยท their own credentials ยท their own access
Chapter 3 ยท The Rule Cards

What can each worker actually do?

Auntie Ama writes a rule card for each worker. They're simple, written in plain ink:

Kwesi's card: "Allowed to open cash box. Allowed to give change. NOT allowed to touch shelves."

Adwoa's card: "Allowed to restock shelves. Allowed to count inventory. NOT allowed near cash box."

Kofi's card: "Allowed to sweep floors. NOT allowed to touch ANY merchandise or cash."

That's a policy. It's a written document that says exactly what someone is allowed (and not allowed) to do. Each worker carries their card. The shop doesn't follow the worker โ€” it follows the card.

IAM Policies โ€” JSON Permissions
Kwesi CASH BOX KWESI'S CARD โœ“ open cash box โœ“ give change โœ— touch shelves โœ“ ALLOWED Adwoa ADWOA'S CARD โœ“ restock shelves โœ“ count inventory โœ— touch cash box โœ— DENIED
Watching the rules
Chapter 4 ยท The Worker Groups

Hire 50 cashiers? Group them up.

Suppose Auntie Ama's business explodes. She now has 20 cashiers, 15 restockers, and 10 cleaners. Writing 45 individual rule cards would be madness. And what if cashier rules need to change? She'd have to update 20 cards.

So she does something smarter. She writes three group cards:

โ€ข "CASHIERS" group card โ€” allowed to use cash boxes.
โ€ข "RESTOCKERS" group card โ€” allowed to handle inventory.
โ€ข "CLEANERS" group card โ€” allowed to use cleaning supplies.

Then she just stamps each worker into a group: "You're a cashier. You're a restocker." When she hires a new cashier, she just adds them to the cashier group โ€” no new rule writing needed.

That's an IAM Group. Permissions live on the group. People join the group. Never assign permissions to individuals when a group will do.

IAM Groups โ€” Permissions in Bulk
Three groups ยท One card each CASHIERS CASHIER RULES โœ“ use cash box โœ“ give receipts + 14 more... 20 cashiers RESTOCKERS RESTOCK RULES โœ“ touch shelves โœ“ count stock + 9 more... 15 restockers CLEANERS CLEAN RULES โœ“ sweep / mop โœ— touch goods + 4 more... 10 cleaners
Chapter 5 ยท The Borrowed Apron

"Wear my apron just for now"

One afternoon, a delivery driver from Tema arrives with new fabric rolls. He needs to walk into the storeroom to drop them off. But he's not a worker โ€” he doesn't have a badge or a key.

Auntie Ama doesn't hire him. She just hands him an apron and says: "Wear this for the next 10 minutes. It gives you access to the storeroom only. When you leave, give it back."

The apron isn't his. He never owned it. He just borrowed it temporarily for one task. When the task is done, he hands it back, and he goes back to being just a delivery driver.

That's an IAM RoleAn IAM Role is an identity that can be temporarily assumed by a user, application, or AWS service. Roles use temporary credentials that expire โ€” perfect for cross-account access, EC2 instances accessing S3, and federated logins.. It's not tied to a specific person. Anyone (or anything) authorized can "assume" the role for a limited time, do their job, then drop it.

This is how an EC2 server reads from an S3 bucket. The server doesn't have a username โ€” it temporarily wears the "S3 access" apron.

IAM Roles โ€” Temporary Apron
STOREROOM Auntie Ama APRON Driver โฑ 10 min ยท STS token โœ“ ACCESS GRANTED
Watching the loan
Chapter 6 ยท The Master Key

The owner's key โ€” lock it away

Remember Auntie Ama's master key from the very beginning? It opens everything. The cash box, the storeroom, the books, the safe in the back, even the ledger she doesn't show anyone.

If a thief gets that key, the entire shop is lost. So Ama keeps it locked in a safe at home and almost never carries it. She uses her own personal cashier badge for daily work. The master key only comes out for emergencies โ€” once a year, maybe.

That's the root user in AWS. It's the email and password you signed up with. It can do everything โ€” including delete the account itself.

The honest truth: after creating your account, log out of root, create a personal IAM user with admin permissions, and use THAT for everything. Never use root for daily work. Enable MFA on root. Lock it away.

Root User โ€” Emergencies Only
๐Ÿ”’ LOCKED MFA โš  NEVER use root for daily work Use IAM user with admin perms "The key that opens everything ยท Use only when nothing else works"
The Map

The whole market, in AWS terms

IAM is the most exam-tested topic for a reason โ€” it's the foundation of AWS security. But you don't need to memorize it. Just remember Ama's stall.

๐Ÿ”‘
Auntie Ama (the owner)
โ†“
Root User

Master key. Can do everything. Use only in emergencies.

๐Ÿชช
Worker name badge
โ†“
IAM User

One per person. Has its own credentials and login.

๐Ÿ“‹
The rule card
โ†“
IAM Policy

JSON document listing what's allowed and what's denied.

๐Ÿ‘ฅ
Worker categories
โ†“
IAM Group

Permissions in bulk. Add a person, they inherit the rules.

๐Ÿฆบ
The borrowed apron
โ†“
IAM Role

Temporary identity. Assumed for a task, then dropped.

"AWS security isn't paranoia. It's just running your shop properly."

Read the story again