A policy that defines who is allowed to assume an IAM role.
Separate from the permissions policy (what can be done), it controls who can use the role itself -- which principal can call AssumeRole -- and commonly appears when configuring cross-account access.
© 2026 ITBGM