AWS Security ChangesHomeSearch

AWS omics: Add 'Trust the workflow owner' warning to workflow sharing

Service: omics · 2026-09-27 · Documentation medium

File: omics/latest/dev/sharing-workflows.md · Type: authz

Summary

Adds the same security warning to the workflow sharing page: running a shared workflow executes the owner's workflow definition and containers as third-party code in the subscriber's account, so use a least-privilege service role and session policy.

Security assessment

Identical security caution to the resource-sharing page: it warns that shared workflows run untrusted owner-supplied code in the consumer's account and directs users to constrain blast radius via least-privilege IAM roles and session policies. It documents best practice rather than a concrete patched weakness.

Evidence

Make sure that you trust the workflow owner before you accept a share. When you run a shared workflow, the workflow definition and container images that the owner provided run in your AWS account. They run with the permissions of the IAM service role that you specify for the run.

Diff

diff --git a/omics/latest/dev/sharing-workflows.md b/omics/latest/dev/sharing-workflows.md
index 1374c28ed..0048b3cb6 100644
--- a//omics/latest/dev/sharing-workflows.md
+++ b//omics/latest/dev/sharing-workflows.md
@@ -20,0 +21,4 @@ When you share a workflow, the subscriber can use any of the workflow versions.
+###### Trust the workflow owner
+
+Make sure that you trust the workflow owner before you accept a share. When you run a shared workflow, the workflow definition and container images that the owner provided run in your AWS account. They run with the permissions of the IAM service role that you specify for the run. The contents of the workflow and its container images aren't visible to you. Running a shared workflow is equivalent to running third-party code in your account. Provide a least-privilege service role, and use a session policy to further restrict permissions for the run. For more information, see [Use session policies to scope down permissions](./permissions-service.html#permissions-service-sessionpolicy).
+