How to5 min readOctober 6, 2026

S3 access for non-technical teams: the complete guide

Everything a company needs to give finance, operations, legal and media staff safe access to files in Amazon S3, without AWS Console logins, in reading order.

JeVaughn Ferguson
Founder, developer
The short version

Keep files in S3, give tools a scoped IAM role instead of keys, and pick the access layer by who needs the files: one link for one file, a component for an app you build, a workspace for teams who need previews, sharing and roles.

Many companies keep contracts, invoices, scans and media in Amazon S3 because it is cheap, durable and already inside their AWS account. The engineers are happy. Everyone else has to ask them for files, or gets an AWS Console login they were never meant to have.

This guide collects our articles on that problem in the order most teams meet it: first the ways people can reach files at all, then how to keep access safe, then what people need once they can see the files, and finally how to choose a tool.

Start here: the ways people can reach S3 files

There are four common answers: a presigned link for one file, an AWS-managed web portal, the Storage Browser component inside an app you build, and a workspace with sign-in and roles. Each fits a different job. The first article compares all four; the second describes what a good business-facing workspace looks like.

Keep access safe: IAM roles, not shared keys

The safest pattern gives a tool a scoped IAM role in your account instead of access keys. An external ID stops another customer of the same tool from pointing it at your bucket, and a bucket policy or prefix scope limits what each team can reach. These articles explain the pieces and show working examples.

Once people can see the files: previews and sharing

Access alone is not enough if every PDF, spreadsheet or iPhone photo has to be downloaded to be opened, or if sharing a file with a client still means a script. Previews in the browser and share links that expire and can be revoked are what make S3 usable day to day.

Choosing a tool

Desktop clients such as Cyberduck, S3 Browser and Transmit suit people comfortable with credentials. AWS's Storage Browser suits teams building their own app. A workspace suits companies where many non-technical people need the same files with roles and an audit trail. These comparisons are honest about when each one wins.

Try it in BucketDesk

Starter is free. Deploy a scoped role with CloudFormation, sign in, and browse, without handing anyone an access key.

Connect a bucket

Primary sources

Discussion

0 comments · open to guests · moderated
Comments appear after a quick review.

Liked this? Get the next article by email. No schedule, no filler, one click to leave.

Keep reading

All writing →
Security8 min

Amazon Bedrock data retention modes: none, default or aws_review for business documents

When you ask AI on AWS about a company document, AWS now lets you choose whether that conversation may be kept. Here is what each choice means and who should make it.data_retention_mode none/default/aws_review/provider_data_share/inherit, project → account → model default resolution, allowed_modes and ValidationException, bedrock:PutAccountDataRetention with the DataRetentionMode condition key, and destination-Region storage under cross-Region inference.

How to8 min

S3 lifecycle rules explained: examples for versioned buckets, delete markers and storage class transitions

Lifecycle rules are how a bucket tidies itself: moving old files somewhere cheaper and clearing out copies nobody needs. Here is how to write them without deleting the wrong thing.Filter And blocks with prefix, tags and ObjectSizeGreaterThan, NoncurrentVersionExpiration with NewerNoncurrentVersions, ExpiredObjectDeleteMarker, AbortIncompleteMultipartUpload, conflict precedence, midnight-UTC rounding and transition request costs.

Product decisions8 min

Amazon Bedrock AgentCore for document agents on S3: what it runs, what it costs, and when you don't need it

AgentCore is AWS's toolkit for running your own AI agents. Here is what it would take to point one at your company's files, and when a simpler tool already answers the question.Runtime microVM sessions (8 hours, 100 MB payloads, 2 vCPU / 8 GB), execution roles that need your own s3:GetObject, Gateway turning Lambda and OpenAPI into MCP tools, vCPU-hour and GB-hour billing with free I/O wait, and Quick's MCP client.