AWS System by Trustle manages access to resources using the IAM Service in AWS. It uses groups, roles, and policies to relate user accounts to resources, rather than direct access policies. Trustle's AWS connector offers deep visibility and management of AWS IAM resources. The connector can be deployed in read-only or read/write mode, based on the AWS policy. Once configured, the Trustle AWS connector continuously monitors AWS IAM and provides a full read-out on all accounts, privileges, and policies. Trustle provides recommendations for adjusting system settings and IAM configurations. The AWS connector collects substantial information from IAM, including usage data, providing a detailed high-level view of AWS configuration. Trustle can alert you to expired tokens that need rotation. It monitors usage patterns for user accounts, groups, and roles, recommending the necessary level of access. Trustle maintains a history of all access requests, workflows, and system changes for security and compliance auditing. With information from AWS and usage data, Trustle recommends improving security by removing unnecessary user access, cleaning up unused accounts, and increasing sensitivity on high-risk resources. Trustle recommends rotating tokens at set intervals, reviewing specific accounts, highlighting accounts with access keys and certificates needing rotation, and enabling multi-factor authentication (MFA) for accounts. Based on metrics of the sensitivity of the resource or service, compared with the amount of usage the account requires, Trustle also identifies opportunities to move these entitlements to Temporary or Just-in-Time, ensuring that access to these resources are guarded by least privilege principles.