UNPKG

@cloud-copilot/iam-data

Version:
895 lines 28.9 kB
{ "acceptinvitation": { "name": "AcceptInvitation", "description": "Grants permission to accept an Amazon Macie membership invitation", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "batchgetcustomdataidentifiers": { "name": "BatchGetCustomDataIdentifiers", "description": "Grants permission to retrieve information about one or more custom data identifiers", "accessLevel": "Read", "resourceTypes": [ { "name": "CustomDataIdentifier", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "batchupdateautomateddiscoveryaccounts": { "name": "BatchUpdateAutomatedDiscoveryAccounts", "description": "Grants permission to an Amazon Macie administrator to change the status of automated sensitive data discovery for one or more accounts in their organization", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "createallowlist": { "name": "CreateAllowList", "description": "Grants permission to create and define the settings for an allow list", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:TagKeys" ], "dependentActions": [] }, "createclassificationjob": { "name": "CreateClassificationJob", "description": "Grants permission to create and define the settings for a sensitive data discovery job", "accessLevel": "Write", "resourceTypes": [ { "name": "ClassificationJob", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:TagKeys" ], "dependentActions": [] }, "createcustomdataidentifier": { "name": "CreateCustomDataIdentifier", "description": "Grants permission to create and define the settings for a custom data identifier", "accessLevel": "Write", "resourceTypes": [ { "name": "CustomDataIdentifier", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:TagKeys" ], "dependentActions": [] }, "createfindingsfilter": { "name": "CreateFindingsFilter", "description": "Grants permission to create and define the settings for a findings filter", "accessLevel": "Write", "resourceTypes": [ { "name": "FindingsFilter", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:TagKeys" ], "dependentActions": [] }, "createinvitations": { "name": "CreateInvitations", "description": "Grants permission to send an Amazon Macie membership invitation", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "createmember": { "name": "CreateMember", "description": "Grants permission to associate an account with an Amazon Macie administrator account", "accessLevel": "Write", "resourceTypes": [ { "name": "Member", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:TagKeys" ], "dependentActions": [] }, "createsamplefindings": { "name": "CreateSampleFindings", "description": "Grants permission to create sample findings", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "declineinvitations": { "name": "DeclineInvitations", "description": "Grants permission to decline Amazon Macie membership invitations", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "deleteallowlist": { "name": "DeleteAllowList", "description": "Grants permission to delete an allow list", "accessLevel": "Write", "resourceTypes": [ { "name": "AllowList", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "deletecustomdataidentifier": { "name": "DeleteCustomDataIdentifier", "description": "Grants permission to delete a custom data identifier", "accessLevel": "Write", "resourceTypes": [ { "name": "CustomDataIdentifier", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "deletefindingsfilter": { "name": "DeleteFindingsFilter", "description": "Grants permission to delete a findings filter", "accessLevel": "Write", "resourceTypes": [ { "name": "FindingsFilter", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "deleteinvitations": { "name": "DeleteInvitations", "description": "Grants permission to delete Amazon Macie membership invitations", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "deletemember": { "name": "DeleteMember", "description": "Grants permission to delete the association between an Amazon Macie administrator account and an account", "accessLevel": "Write", "resourceTypes": [ { "name": "Member", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "describebuckets": { "name": "DescribeBuckets", "description": "Grants permission to retrieve statistical data and other information about S3 buckets that Amazon Macie monitors and analyzes", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "describeclassificationjob": { "name": "DescribeClassificationJob", "description": "Grants permission to retrieve information about the status and settings for a sensitive data discovery job", "accessLevel": "Read", "resourceTypes": [ { "name": "ClassificationJob", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "describeorganizationconfiguration": { "name": "DescribeOrganizationConfiguration", "description": "Grants permission to retrieve information about the Amazon Macie configuration settings for an AWS organization", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "disablemacie": { "name": "DisableMacie", "description": "Grants permission to disable an Amazon Macie account, which also deletes Macie resources for the account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "disableorganizationadminaccount": { "name": "DisableOrganizationAdminAccount", "description": "Grants permission to disable an account as the delegated Amazon Macie administrator account for an AWS organization", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "disassociatefromadministratoraccount": { "name": "DisassociateFromAdministratorAccount", "description": "Grants permission to an Amazon Macie member account to disassociate from its Macie administrator account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "disassociatefrommasteraccount": { "name": "DisassociateFromMasterAccount", "description": "Grants permission to an Amazon Macie member account to disassociate from its Macie administrator account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "disassociatemember": { "name": "DisassociateMember", "description": "Grants permission to an Amazon Macie administrator account to disassociate from a Macie member account", "accessLevel": "Write", "resourceTypes": [ { "name": "Member", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "enablemacie": { "name": "EnableMacie", "description": "Grants permission to enable and specify the configuration settings for a new Amazon Macie account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "enableorganizationadminaccount": { "name": "EnableOrganizationAdminAccount", "description": "Grants permission to enable an account as the delegated Amazon Macie administrator account for an AWS organization", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getadministratoraccount": { "name": "GetAdministratorAccount", "description": "Grants permission to retrieve information about the Amazon Macie administrator account for an account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getallowlist": { "name": "GetAllowList", "description": "Grants permission to retrieve the settings and status of an allow list", "accessLevel": "Read", "resourceTypes": [ { "name": "AllowList", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "getautomateddiscoveryconfiguration": { "name": "GetAutomatedDiscoveryConfiguration", "description": "Grants permission to retrieve the configuration settings and status of automated sensitive data discovery for an Amazon Macie administrator account, organization, or standalone account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getbucketstatistics": { "name": "GetBucketStatistics", "description": "Grants permission to retrieve aggregated statistical data for all the S3 buckets that Amazon Macie monitors and analyzes", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getclassificationexportconfiguration": { "name": "GetClassificationExportConfiguration", "description": "Grants permission to retrieve the settings for exporting sensitive data discovery results", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getclassificationscope": { "name": "GetClassificationScope", "description": "Grants permission to retrieve the classification scope settings for an account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getcustomdataidentifier": { "name": "GetCustomDataIdentifier", "description": "Grants permission to retrieve information about the settings for a custom data identifier", "accessLevel": "Read", "resourceTypes": [ { "name": "CustomDataIdentifier", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "getfindingstatistics": { "name": "GetFindingStatistics", "description": "Grants permission to retrieve aggregated statistical data about findings", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getfindings": { "name": "GetFindings", "description": "Grants permission to retrieve the details of one or more findings", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getfindingsfilter": { "name": "GetFindingsFilter", "description": "Grants permission to retrieve information about the settings for a findings filter", "accessLevel": "Read", "resourceTypes": [ { "name": "FindingsFilter", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "getfindingspublicationconfiguration": { "name": "GetFindingsPublicationConfiguration", "description": "Grants permission to retrieve the configuration settings for publishing findings to AWS Security Hub", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getinvitationscount": { "name": "GetInvitationsCount", "description": "Grants permission to retrieve the count of Amazon Macie membership invitations that were received by an account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getmaciesession": { "name": "GetMacieSession", "description": "Grants permission to retrieve information about the status and configuration settings for an Amazon Macie account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getmasteraccount": { "name": "GetMasterAccount", "description": "Grants permission to retrieve information about the Amazon Macie administrator account for an account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getmember": { "name": "GetMember", "description": "Grants permission to retrieve information about an account that's associated with an Amazon Macie administrator account", "accessLevel": "Read", "resourceTypes": [ { "name": "Member", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "getresourceprofile": { "name": "GetResourceProfile", "description": "Grants permission to retrieve sensitive data discovery statistics and the sensitivity score for an S3 bucket", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getrevealconfiguration": { "name": "GetRevealConfiguration", "description": "Grants permission to retrieve the status and configuration settings for retrieving occurrences of sensitive data reported by findings", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getsensitivedataoccurrences": { "name": "GetSensitiveDataOccurrences", "description": "Grants permission to retrieve occurrences of sensitive data reported by a finding", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getsensitivedataoccurrencesavailability": { "name": "GetSensitiveDataOccurrencesAvailability", "description": "Grants permission to check whether occurrences of sensitive data can be retrieved for a finding", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getsensitivityinspectiontemplate": { "name": "GetSensitivityInspectionTemplate", "description": "Grants permission to retrieve the sensitivity inspection template settings for an account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getusagestatistics": { "name": "GetUsageStatistics", "description": "Grants permission to retrieve quotas and aggregated usage data for one or more accounts", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "getusagetotals": { "name": "GetUsageTotals", "description": "Grants permission to retrieve aggregated usage data for an account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listallowlists": { "name": "ListAllowLists", "description": "Grants permission to retrieve a subset of information about all the allow lists for an account", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listautomateddiscoveryaccounts": { "name": "ListAutomatedDiscoveryAccounts", "description": "Grants permission to retrieve the status of automated sensitive data discovery for an account", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listclassificationjobs": { "name": "ListClassificationJobs", "description": "Grants permission to retrieve a subset of information about the status and settings for one or more sensitive data discovery jobs", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listclassificationscopes": { "name": "ListClassificationScopes", "description": "Grants permission to retrieve a subset of information about the classification scope for an account", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listcustomdataidentifiers": { "name": "ListCustomDataIdentifiers", "description": "Grants permission to retrieve information about all custom data identifiers", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listfindings": { "name": "ListFindings", "description": "Grants permission to retrieve a subset of information about one or more findings", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listfindingsfilters": { "name": "ListFindingsFilters", "description": "Grants permission to retrieve information about all findings filters", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listinvitations": { "name": "ListInvitations", "description": "Grants permission to retrieve information about all the Amazon Macie membership invitations that were received by an account", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listmanageddataidentifiers": { "name": "ListManagedDataIdentifiers", "description": "Grants permission to retrieve information about managed data identifiers", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listmembers": { "name": "ListMembers", "description": "Grants permission to retrieve information about the Amazon Macie member accounts that are associated with a Macie administrator account", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listorganizationadminaccounts": { "name": "ListOrganizationAdminAccounts", "description": "Grants permission to retrieve information about the delegated Amazon Macie administrator account for an AWS organization", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listresourceprofileartifacts": { "name": "ListResourceProfileArtifacts", "description": "Grants permission to retrieve information about objects that Amazon Macie selected from an S3 bucket for automated sensitive data discovery", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listresourceprofiledetections": { "name": "ListResourceProfileDetections", "description": "Grants permission to retrieve information about the types and amount of sensitive data that Amazon Macie found in an S3 bucket", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listsensitivityinspectiontemplates": { "name": "ListSensitivityInspectionTemplates", "description": "Grants permission to retrieve a subset of information about the sensitivity inspection template for an account", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listtagsforresource": { "name": "ListTagsForResource", "description": "Grants permission to retrieve the tags for an Amazon Macie resource", "accessLevel": "Read", "resourceTypes": [ { "name": "AllowList", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "ClassificationJob", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "CustomDataIdentifier", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "FindingsFilter", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "Member", "required": false, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "putclassificationexportconfiguration": { "name": "PutClassificationExportConfiguration", "description": "Grants permission to create or update the settings for storing sensitive data discovery results", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "putfindingspublicationconfiguration": { "name": "PutFindingsPublicationConfiguration", "description": "Grants permission to update the configuration settings for publishing findings to AWS Security Hub", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "searchresources": { "name": "SearchResources", "description": "Grants permission to retrieve statistical data and other information about AWS resources that Amazon Macie monitors and analyzes", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "tagresource": { "name": "TagResource", "description": "Grants permission to add or update the tags for an Amazon Macie resource", "accessLevel": "Tagging", "resourceTypes": [ { "name": "AllowList", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "ClassificationJob", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "CustomDataIdentifier", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "FindingsFilter", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "Member", "required": false, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:TagKeys" ], "dependentActions": [] }, "testcustomdataidentifier": { "name": "TestCustomDataIdentifier", "description": "Grants permission to test a custom data identifier", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "untagresource": { "name": "UntagResource", "description": "Grants permission to remove tags from an Amazon Macie resource", "accessLevel": "Tagging", "resourceTypes": [ { "name": "AllowList", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "ClassificationJob", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "CustomDataIdentifier", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "FindingsFilter", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "Member", "required": false, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:TagKeys" ], "dependentActions": [] }, "updateallowlist": { "name": "UpdateAllowList", "description": "Grants permission to update the settings for an allow list", "accessLevel": "Write", "resourceTypes": [ { "name": "AllowList", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "updateautomateddiscoveryconfiguration": { "name": "UpdateAutomatedDiscoveryConfiguration", "description": "Grants permission to change the status of automated sensitive data discovery for an Amazon Macie administrator account, organization, or standalone account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "updateclassificationjob": { "name": "UpdateClassificationJob", "description": "Grants permission to change the status of a sensitive data discovery job", "accessLevel": "Write", "resourceTypes": [ { "name": "ClassificationJob", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:TagKeys" ], "dependentActions": [] }, "updateclassificationscope": { "name": "UpdateClassificationScope", "description": "Grants permission to update the classification scope settings for an account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "updatefindingsfilter": { "name": "UpdateFindingsFilter", "description": "Grants permission to update the settings for a findings filter", "accessLevel": "Write", "resourceTypes": [ { "name": "FindingsFilter", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:TagKeys" ], "dependentActions": [] }, "updatemaciesession": { "name": "UpdateMacieSession", "description": "Grants permission to an Amazon Macie administrator account to suspend or re-enable Macie for a member account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "updatemembersession": { "name": "UpdateMemberSession", "description": "Grants permission to an Amazon Macie administrator account to suspend or re-enable a Macie member account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "updateorganizationconfiguration": { "name": "UpdateOrganizationConfiguration", "description": "Grants permission to update Amazon Macie configuration settings for an AWS organization", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "updateresourceprofile": { "name": "UpdateResourceProfile", "description": "Grants permission to update the sensitivity score for an S3 bucket", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "updateresourceprofiledetections": { "name": "UpdateResourceProfileDetections", "description": "Grants permission to update the sensitivity scoring settings for an S3 bucket", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "updaterevealconfiguration": { "name": "UpdateRevealConfiguration", "description": "Grants permission to update the status and configuration settings for retrieving occurrences of sensitive data reported by findings", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "updatesensitivityinspectiontemplate": { "name": "UpdateSensitivityInspectionTemplate", "description": "Grants permission to update the sensitivity inspection template settings for an account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] } }