An IAM role assumed by an AWS service itself to operate other resources.
For example, if a Lambda function accesses S3, you grant the necessary permission to the service role attached to the function. A trust policy controls which service can assume the role.
© 2026 ITBGM