Summary
A permissions boundary is an advanced feature in which a managed policy is used to set the maximum permissions that an identity-based policy can grant to an IAM entity, such as a user or role. This feature can be used to limit the scope of the execution role that an application's template creates for each of its functions, and any roles that are added to the template.
1
2
3
According to