{"id":"s3-policy-default-allow","text":"`check_bucket_policy` returns `True` (allow) when no policies exist or when no policy matches — opposite of AWS IAM's default-deny.","truth_value":"IN","source":"entries/2026/06/05/s3-object-storage-s3_object_storage.md","source_url":"","source_hash":"","justifications":[],"dependents":["access-control-defaults-favor-availability-over-security"],"metadata":{},"created_at":"","updated_at":"","reviewed_at":"","verified_at":"","retracted_at":"","explanation":{"steps":[{"node":"s3-policy-default-allow","truth_value":"IN","reason":"premise"}]}}