You have full control over the incoming event object, so you should have complete control over inputs. Connections to services depends on your setup of course. If you can route to your VPC, you can access those private resources too. By default, it will use your local AWS keypair, but I believe there is a way to assume an IAM role as well.