S3 Accounts
Introduction
Accounts in S3 are logical containers that can hold users, groups, and roles. An account in SCS3 is associated with an S3 project instance.
Account Users
Users are entities that can interact with the S3 API.
They authenticate with their access keys to prove their identity and perform S3 queries if the policies that are enforced allow them to.
Users can create buckets and store objects in them, but the account is the sole owner. This makes a departure of a user hassle-free.
Account Groups
Groups contain users, and you can attach policies to a group or allow a group to perform certain actions via bucket policies. IAM policies on a group are enforced on all the users of the group. This makes it easier to manage complex policies by adding or removing a user of a group instead of creating a tailor-made policy for each user each time.
Account Roles
Roles allow a user to act as if they were a different user for a limited time. Policies can be attached to roles, and policies can reference roles. Roles help in giving users temporary access to your resources.
Managing Accounts
AWS CLI is the primary tool we use to interact with S3 and most of the examples in the documentation use that.
Managing Users
The below examples create a user, their access keys, then delete the user.
% aws --profile myprof iam create-user --user-name test-user
{
"User": {
"Path": "/",
"UserName": "test-user",
"UserId": "add99417-1b36-46f8-a7b4-bb74a3679d47",
"Arn": "arn:aws:iam::RGW97190984419934537:user/test-user",
"CreateDate": "2026-09-11T15:04:44.887013+00:00"
}
}
% aws --profile myprof iam create-access-key --user-name test-user
{
"AccessKey": {
"UserName": "test-user",
"AccessKeyId": "CUY3WWED8R0Y6LOV651X",
"Status": "Active",
"SecretAccessKey": "VMePDOQfiXRm9r9YPTlMiZbNMBlNMktCnWeoUtkq",
"CreateDate": "2026-09-11T15:07:26.947341+00:00"
}
}
% aws --profile myprof iam update-access-key \
--user-name test-user \
--access-key CUY3WWED8R0Y6LOV651X \
--status Inactive
% aws --profile myprof iam list-access-keys --user-name test-user
{
"AccessKeyMetadata": [
{
"UserName": "test-user",
"AccessKeyId": "CUY3WWED8R0Y6LOV651X",
"Status": "Inactive",
"CreateDate": "2026-09-11T15:07:26.947341+00:00"
}
]
}
% aws --profile myprof iam delete-access-key \
--user-name test-user \
--access-key CUY3WWED8R0Y6LOV651X
% aws --profile myprof iam delete-user --user-name test-user
Managing Groups
In the following examples we will create groups, add users and more.
% aws --profile myprof iam create-group --group-name guests
{
"Group": {
"Path": "/",
"GroupName": "guests",
"GroupId": "fe507636-5249-403f-9c68-31319dd44116",
"Arn": "arn:aws:iam::RGW97190984419934537:group/guests"
}
}
% aws --profile myprof iam add-user-to-group \
--user-name test-user --group-name guests
# There is always an admin group, don't delete it!
# You will lose access to the project
# And then you must contact support to restore access
% aws --profile myprof iam list-groups
{
"Groups": [
{
"Path": "/",
"GroupName": "admins",
"GroupId": "0b85f784-1ce1-4f34-9847-75ed1ccf984c",
"Arn": "arn:aws:iam::RGW97190984419934537:group/admins"
},
{
"Path": "/",
"GroupName": "guests",
"GroupId": "fe507636-5249-403f-9c68-31319dd44116",
"Arn": "arn:aws:iam::RGW97190984419934537:group/guests"
}
]
}
% aws --profile myprof iam get-group --group-name guests
{
"Users": [
{
"Path": "/",
"UserName": "test-user",
"UserId": "add99417-1b36-46f8-a7b4-bb74a3679d47",
"Arn": "arn:aws:iam::RGW97190984419934537:user/test-user"
}
],
"Group": {
"Path": "/",
"GroupName": "guests",
"GroupId": "fe507636-5249-403f-9c68-31319dd44116",
"Arn": "arn:aws:iam::RGW97190984419934537:group/guests"
}
}
% aws --profile myprof iam remove-user-from-group \
--user-name test-user --group-name guests
% aws --profile myprof iam delete-group --group-name guests
Managing Roles + STS
Please visit STS.