Access Denied, and the Policy Says Allow
The report, in their words
The nightly export job failed at 02:10 with AccessDenied: not authorized to perform s3:PutObject on arn:aws:s3:::exports-prod/nightly/2026-08-24.csv. The on-call engineer attached a policy granting s3:* on that bucket to the job's role and retried. Same denial. It ran successfully every night for eight months and nothing in the job changed.
Pull evidence
One item at a time, and nothing here tells you which one matters. Deciding what is worth looking at is most of the diagnosis.
Who is the caller, actually?
Simulate the exact call: principal, action, resource
What changed in the account yesterday evening
The request the exporter actually sends
Did anything comparable keep working?
The role's attached identity policies
The bucket policy
Credential freshness on the instance
0 of 8 inspected. You are not required to open all of them — a real investigation is judged on how few you needed.
What is your diagnosis?
Commit to one. Nothing below is shown until you do.
Guessing wrong and being told exactly why is the point of this page. Reading the answer first is not practice.