{"id":"fis-ssm-passrole-scoped-to-ssm-service","text":"The AWSFaultInjectionSimulatorSSMAccess policy scopes `iam:PassRole` with a condition restricting it to `\"iam:PassedToService\": \"ssm.amazonaws.com\"` only.","truth_value":"IN","source":"entries/2026/03/12/aws-managed-policy-latest-reference-AWSFaultInjectionSimulatorSSMAccesshtml.md","source_url":"","source_hash":"7ff37c919baa9a8f","justifications":[],"dependents":[],"metadata":{},"explanation":{"steps":[{"node":"fis-ssm-passrole-scoped-to-ssm-service","truth_value":"IN","reason":"premise"}]}}