Create IAM user with group membership in AWS
Automatically create an IAM user in AWS from a Slack request with Stepwork. Set the user name, then add the groups that grant their permissions.
- Use case
- Access managementIT
- Best for
- Cloud Administrator, IT Administrator
- Applications used
AWS
Slack
- Business outcome
- Time savings
The problem
Cloud access waits on the one person who knows IAM.
A new engineer needs AWS access, and the request sits until a cloud admin has time. Then the admin creates the IAM user and attaches permissions from a checklist, or from whatever the last person in that role had.
Permissions attached straight to a user are hard to review later. Two people in the same role end up with different access, and nobody can say why.
The outcome
The user gets their permissions from groups
Stepwork creates the IAM user and adds them to each group in the request. Permissions come from those groups, so two people in the same role match. The run records who asked and which groups were added.
- The user is created with the name from the request.
- Every group in the request is added.
- A user name that is already taken stops the run.
The process
From Slack request to a ready IAM user
A teammate posts the request in Slack. Stepwork creates the user in the IAM console and adds their groups, in the same order every time.
- Step 1
Request it in Slack
A teammate posts the user name and the IAM groups in the access channel. That message starts the flow, and Stepwork records who asked and when.

- Step 2
Create the user
Stepwork signs in to the AWS console, opens IAM, and creates the user with that name. If the name is already taken, the run stops instead of changing the existing user.

- Step 3
Add their groups
Stepwork adds the user to each group from the request. The groups carry the permission policies, so nothing is attached to the user directly.

- Step 4
Confirm and reply in Slack
Stepwork checks the user’s group memberships, then posts the result back in Slack.

Why Stepwork
Permissions come from groups, every time
The recorded path adds groups and never attaches a policy to the user directly. A deterministic agent follows that path for every request, so access stays easy to review.
Similar use cases
Similar use cases
Deactivate IAM user in AWSDisables console access and deactivates credentials for an IAM user in the AWS console.
Create user and assign groups in OktaCreates a new Okta user with name, email, and title, then assigns the group memberships that grant their app entitlements.
Invite member with team assignment in GitHubInvites a new member to the GitHub org and adds them to the teams that grant their repo access.
FAQ





