S3Policies S3 Access Control Lists Policies Names must be globally unique Cloud trail logs any activity using the S3 API Additional costs Principle in policy Entity you are blocking or allowing access to IAM user S3 bucket S3 resource