# IAM permissions wiped out

**URL:** <https://forum.serverless.com/t/iam-permissions-wiped-out/9156>\
**Category:** Serverless Framework\
**Tags:** lambda, iam\
**Created:** [August 26, 2019, 2:23pm UTC](https://forum.serverless.com/t/iam-permissions-wiped-out/9156 "2019-08-26T14:23:45Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![acchaulk](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/acchaulk/32/3812_2.png) [@acchaulk](https://forum.serverless.com/u/acchaulk)\
**Post date:** [August 26, 2019, 2:23pm UTC](https://forum.serverless.com/t/iam-permissions-wiped-out/9156/1 "2019-08-26T14:23:45Z")

</div>

I have a lambda function that uses the default serverless IAM role, where I assign a few inline `iamRoleStatements`. In an external application I dynamically assign different SQS permissions to the default serverless policy.  
After upgrading from 1.38.0 to 1.50.0 (same with 1.45.0), the externally assigned permissions are removed from the policy. I am still digging through the changelog, but was there a breaking change made along the way, or should the default serverless role be considered immutable?
