A burst of ListPolicies / GetPolicyVersion calls looked like reconnaissance but traced back to a scheduled least-privilege audit job running under ci-runner-role. Closed benign.
What happened
09:58◆ Observer
Spike in IAM policy enumeration API calls
10:01◆ Hunter
Source attributed to ci-runner-role (scheduled)
10:04◆ Investigator
Matched to the nightly access-review job; closed benign