{"id":"dynamodb-root-can-always-delete-resource-policy","text":"The AWS account root principal can always call `DeleteResourcePolicy` on DynamoDB, even if the resource-based policy explicitly denies root access, preventing accidental lockout.","truth_value":"IN","source":"entries/2026/03/11/amazondynamodb-latest-APIReference-API_DeleteResourcePolicyhtml.md","source_url":"","source_hash":"cee8ddf9ade7e259","justifications":[],"dependents":[],"metadata":{},"explanation":{"steps":[{"node":"dynamodb-root-can-always-delete-resource-policy","truth_value":"IN","reason":"premise"}]}}