Back to library
Security & IAM·n8n workflow

IAM Permission Drift Audit

Weekly: compare current IAM role assignments to baseline; detect unexpected access escalations or permission creep; alert with remediation steps.

Overview

**What it does**: Weekly schedule → query cloud IAM current permissions (AWS IAM roles/policies, GCP service accounts, Azure Entra) → compare to baseline/RBAC policy → code detects drift (service account has role not in baseline, principal granted overly-permissive policy) → LLM analyzes: who has unexpected access, risk level, likely cause (manual grant, config error, service account sprawl) → Slack to #security-alerts with violations and remediation. **Setup (4 steps)**: 1. Configure cloud IAM: AWS (IAM API), GCP (IAM API), Azure (Entra API) 2. Define RBAC baseline: expected role mappings (owner=admin, engineer=EC2+RDS read, dev=sandbox-only) 3. Set critical resources: which resources trigger high-severity alerts (prod databases, payment systems) 4. Configure Slack channel: #security-alerts **Apps/nodes**: Schedule, HTTP request (IAM API), code node (drift comparison), Claude/OpenAI (analysis), Slack. **Credentials required**: Cloud IAM API key, OpenAI account, Slack workspace. **Difficulty**: Medium | **Setup time**: 10 minutes. **Business outcome**: Permission creep caught weekly → access ↑ controlled, least-privilege ↑ enforced, compliance audits ↑ pass, security ↑.

What's included

Importable n8n workflow (JSON)
Real, wired nodes — trigger, logic, and actions
Setup notes: which credentials to connect
Free updates when the workflow changes
Commercial-use license — keep and customize
Email support if you get stuck

Inside this workflow

Weekly ScheduleFetch Current …Fetch Expected…Detect Permiss…Drift Detected?Analyze DriftAlert Data TeamNo Drift

Quickstart

  1. 01

    Download the JSON

    With an active Library Pass, download the workflow file right from this page or your dashboard.

  2. 02

    Import into n8n

    Choose Import from File and select the downloaded JSON. The full agent graph appears, ready to configure.

  3. 03

    Plug in credentials

    Each integration node prompts for credentials on first run. The setup guide lists every credential the agent expects.

  4. 04

    Activate and test

    Run once with sample input, confirm the expected output, then flip the activate toggle.

Frequently Asked Questions

How do I import this workflow into n8n?
Download the JSON file from your Library Pass, go to your n8n workspace, click the import button, select "Import from File", and upload the JSON. The entire workflow graph will load instantly, ready for configuration.
What credentials do I need to provide?
Each workflow lists required credentials in its description (e.g., Slack API key, GitHub token, PagerDuty account). You connect your own credentials—the workflow file contains only placeholder names, no actual API keys or secrets.
Are the credentials included in the JSON file?
No. For security, credential IDs are sanitized before distribution. You connect your own accounts when you first run the workflow. n8n will prompt you to authenticate each service.
Can I edit or customize the workflow after importing?
Yes, absolutely. Once imported, the workflow is yours to modify. You can change node logic, add/remove steps, adjust schedules, or integrate with different services. All changes are saved in your n8n workspace.
What n8n version is required?
These workflows use standard n8n-nodes-base node types (released 2022+). They work on n8n Cloud, self-hosted versions 0.180+, and Docker deployments. Community nodes (if required) are noted in the workflow description.
What if something breaks after I import it?
Check the workflow description for setup steps and credential names. Most issues are credential-related. If you get stuck, email support@autoflowworks.com with a screenshot of the error, and we'll help you troubleshoot.
Can I use this workflow for my customers or business?
Yes. The commercial-use license lets you keep, customize, and deploy the workflow for your business or clients. You can redistribute customized versions (except the original unmodified JSON without a valid Library Pass).
Will the workflow receive updates?
Yes. When we improve a workflow (fix bugs, add features, optimize node types), you'll get the updated JSON for free. Check your Library Pass dashboard for new versions.
Do I need n8n Pro or a paid plan?
Not necessarily. These workflows run on n8n Free if you have enough execution time and storage. For production use (frequent triggers, high data volumes, many webhooks), you may want n8n Cloud Pro or higher. Check n8n's pricing for details.
Can I ask for a custom workflow?
Yes! We offer custom workflow design for specific DevOps/SRE use cases. Visit /custom-solutions or email support@autoflowworks.com with your requirements for a quote.

Reviews (0)

No reviews yet. Be the first.

Sign in to leave a review.

Library Pass

Included with any pass

This agent — and every other in the library — comes with a Library Pass. One pass, the whole catalog.

Get a Library Pass
  • Every agent in the library
  • All new releases while active
  • Unlimited downloads
  • Commercial-use license
  • Priority email support
  • 30-day money-back guarantee
Browse the full library →