The only way I've really been able to understand it well is by writing code that uses boto and seeing what errors out lol.
I've found some really interesting bugs/inconsistencies too. Nothing horrible but its def unintuitive sometimes.
Haven't had time to productise it yet. I think doing this makes you quite a bit safer, because it means you don't end up giving up and allowing more than you need. However, you still need to understand which actions shouldn't be allowed, so it's not the whole solution.
That said, if a customer has to fuzz a platform's settings to discern their effect, the UX definitely needs work.
And if you can't figure security out by yourself, pay someone to hold your hand.
This. Security is as much a tradition as it is a set of technologies. Its better to learn from a master than from a costly mistake, and its better to learn how to do it rather than to pay to have it done for you.