Which NC2 permissions am I missing?

Pick the identity, paste what it holds, and see the gaps against the permission lists in the public NC2 user guides. It all runs in your browser: nothing you paste is sent anywhere.

Is this page right? Every example above has an expected answer computed separately in Python: Azure with the CLI tool's own matching function, Google Cloud with its exact-match rule, and AWS with an independent policy evaluator. Role and policy definitions are copied from Microsoft's and AWS's published references. Run the checks here, in your browser, against the code this page is actually using.
What this page can't tell you. It compares lists; it doesn't ask the cloud. It can't see Azure deny assignments, AWS Service Control Policies or permission boundaries, Google Cloud organization policies, or grants inherited from a folder, organization or group. For that, run the read-only command-line tool in your cloud shell, signed in as yourself: github.com/cloudlabworks/nc2-iam-preflight. It also separates MISSING (an IAM grant fixes it) from BLOCKED (a policy above IAM denies it). Background: why ask the cloud, not the checklist.