Is there any way to block the creation of policies containing specific permissions or resources? I know this can be trivially circumvented but if this tool is used in ci/cd it can be a good gate.
I should also mention that the IAM authoring aspect of this tool is more mature than the policy analysis feature.
In CI/CD, if you are using Terraform, I suggest using Open Policy Agent for blocking access to certain resources by evaluating a Terraform plan. I suppose it's also possible to use OPA to evaluate the JSON output of a policy_sentry YML file.
Hope this helps.
Here's an example of using OPA + Conftest with Terraform that you might be interested in: https://github.com/kmcquade/conftest-terraform-multifolder-p...
I haven't used it in production. It uses an even-more-baroque syntax than terraform's HCL dialect, and using it kind of assumes that all your modifications go through terraform.