The boundary held. Everything forbidden was refused; everything needed was permitted.
| probe | expected | result | what AWS said |
| read the proof bucket | deny | denied | An error occurred (AccessDenied) when calling the ListObjectsV2 operation: User: arn:aws:sts::308468018636:assumed-role/enclavize-apply/i-0ccde4e2b974c87f3 is |
| write the dashboard bucket | deny | denied | An error occurred (AccessDenied) when calling the PutObject operation: User: arn:aws:sts::308468018636:assumed-role/enclavize-apply/i-0ccde4e2b974c87f3 is not |
| delete the admin role | deny | denied | An error occurred (AccessDenied) when calling the DeleteRole operation: User: arn:aws:sts::308468018636:assumed-role/enclavize-apply/i-0ccde4e2b974c87f3 is not |
| unlock the console | deny | denied | aws: [ERROR]: argument operation: Found invalid choice 'delete-console-authorization-configuration' usage: aws [options] <command> <subcommand> [<subcommand> |
| list registered domains | deny | denied | An error occurred (AccessDeniedException) when calling the ListDomains operation: User: arn:aws:sts::308468018636:assumed-role/enclavize-apply/i-0ccde4e2b974c8 |
| rewrite proof.20260804.click | deny | denied | An error occurred (AccessDenied) when calling the ChangeResourceRecordSets operation: User: arn:aws:sts::308468018636:assumed-role/enclavize-apply/i-0ccde4e2b9 |
| create an unbounded role | deny | denied | An error occurred (AccessDenied) when calling the CreateRole operation: User: arn:aws:sts::308468018636:assumed-role/enclavize-apply/i-0ccde4e2b974c87f3 is not |
| create my own bucket | allow | allowed | { "Location": "/evize-app-308468018636", "BucketArn": "arn:aws:s3:::evize-app-308468018636" } |
| describe my own instances | allow | allowed | { "Reservations": [ { "ReservationId": "r-04cdd826fc0a4edb7", "OwnerId": "308468018636", "Groups": [], |
| use step functions for myself | allow | allowed | { "stateMachines": [ { "stateMachineArn": "arn:aws:states:us-east-1:308468018636:stateMachine:enclavize-apply", "name": "enc |