- Neptune adds tag‑based access control (TBAC) for IAM, allowing policies to use resource and principal tags to restrict data‑plane actions.
- Administrators can grant neptune-db:* actions only to clusters whose tags match the IAM principal’s tags, reducing lateral access and supporting organization‑wide guardrails via SCPs.
- Requires engine version 1.2.0.0+ with IAM authentication enabled and is available in all AWS regions.