ASTRA: Graph-Grounded LLM Refinement of Least-Privilege IAM Policies
Abstract
Enforcing least privilege in cloud systems requires reconciling changing policy state with fragmented evidence of application intent and observed behavior. We present ASTRA, a graph-grounded generative AI framework that converts heterogeneous AWS evidence into ranked, reviewable policy recommendations. ASTRA constructs a provenance-preserving access graph from configuration, workload, CloudTrail and network evidence to estimate permission necessity. A deterministic compiler produces an evidence-supported Terraform/IAM candidate, and a validator-constrained LLM jointly interprets workload, identity, dependency, resource and usage context to resolve scopes and conditions that are difficult to encode as fixed rules. The refined edits are validated, grouped across affected policies or templates and ranked using permission necessity and security risk. On 483 expert-labeled examples, the selected LLM achieved 96.5\% policy validity and 92.9\% gated recall; SREs accepted 20 of 27 findings (74\%) in a production AWS evaluation.