IAM Users = Who/what (identity) Groups = Role (permissions) Policies = What they can do (permissions) - Updated to attach to group names