A policy that sets access permissions on a resource, such as an S3 bucket, rather than on an IAM user.
It defines, from the resource's side, who (which principal) can access it -- a method commonly used to allow cross-account access.
© 2026 ITBGM