Overview
IAM roles, commonly referred to as roles, are virtual identities similar to user identities and can be associated with permissions to access resources. However, they lack identity certification keys and must be assumed by a trusted entity for proper use.
Roles serve as a bridge to grant access permissions to users, applications, or services requiring cloud account resource access. For example, you can authorize temporary resource access for external users, applications, or services, enabling cross-account resource sharing, or provide temporary access to sensitive resources for IAM users within your account.
This document explains the concepts and working principles of roles, as well as how to meet daily account and resource management needs through roles.
