Access Permission Matrix Auditor

Evaluate an entered role-resource-action permission model and report effective grants, denials and contradictory rules.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Evaluate matrix controls

One JSON object with roles, resources, actions and rules. Each rule is [role, resource, action, effect] and effect is allow or deny. Up to 10,000 role-resource-action cells.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use Access Permission Matrix Auditor

  1. Supply the access model as json using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the access permission matrix auditor.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: Access Permission Matrix Auditor

Compare user-entered roles/resources/actions to find uncovered or contradictory grants. This example uses synthetic public data.

You add
Access model as JSON: { "roles": [ "editor", "viewer" ], "resources": [ "article", "comment" ], "actions": [ "read", "write" ], "rules": [ [ "viewer", "*", "read", "allow" ], [ "editor", "*", "*", "allow" ], [ "editor", "article", "write", "deny" ], [ "editor", "article", "write", "allow" ] ], "assignments": { "ada": "editor", "ben": "viewer", "cara": "administrator" } }
You get
8 cells: 5 allowed, 3 denied (2 by default), 1 contradictory. unknown-role | Principal cara is assigned the role "administrator", which is not in the role list. contradiction | 1 cell match both an allow rule and a deny rule; deny wins every time. uncovered | 2 of 8 cells match no rule at all and are denied by default.

Options

Dimensions and rules
Declare the supported roles, resources and actions before applying exact or supported wildcard rules. Unknown names must be corrected.
Effective cells
A denial overrides a matching allowance in this model. A cell with no allowance remains denied rather than inheriting an assumed permission.

Supported inputs and limits

Bounded declarative model only. No live IAM connection, application authorization test, automatic remediation or security certification.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

The precedence rule is part of the result

This model uses its declared deny-overrides policy and default denial. It can show contradictory rules or uncovered cells, but another authorization system may use different inheritance or precedence. Keep the model and result together when reviewing an intended policy; no account or permission is changed.

Questions about Access Permission Matrix Auditor

Which conflicting rule wins?

The page’s declared model uses deny-overrides; another system may differ.

What happens without a grant?

The model defaults to denial.

Will it change user access?

No. It generates a review matrix from entered declarations.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem