Browse every AWS IAM action, resource type, and condition key. Understand exactly what permissions your policies need.
a4b:*aiops:*execute-api:*apigateway:*apigateway:*appflow:*app-integrations:*arc-zonal-shift:*appstream:*arc-region-switch:*athena:*dsql:*bedrock:*bedrock-agentcore:*bedrock-mantle:*braket:*chime:*clouddirectory:*cloudfront:*cloudfront-keyvaluestore:*cloudsearch:*cloudwatch:*applicationinsights:*application-signals:*evidently:*internetmonitor:*logs:*networkmonitor:*oam:*observabilityadmin:*synthetics:*codecatalyst:*codeguru:*codeguru-profiler:*codeguru-reviewer:*codeguru-security:*codewhisperer:*cognito-identity:*cognito-sync:*cognito-idp:*comprehend:*comprehendmedical:*connect:*cases:*profile:*health-agent:*connect-campaigns:*voiceid:*dlm:*datazone:*detective:*devops-guru:*docdb-elastic:*dynamodb:*dax:*ec2:*autoscaling:*imagebuilder:*ec2-instance-connect:*ecs-mcp:*eks-auth:*eks-mcp:*ebs:*ecr:*ecr-public:*ecs:*elasticfilesystem:*eks:*elasticmapreduce:*elastictranscoder:*evs:*elasticache:*emr-containers:*emr-serverless:*events:*pipes:*scheduler:*schemas:*finspace:*finspace-api:*forecast:*frauddetector:*freertos:*fsx:*gamelift:*gameliftstreams:*groundtruthlabeling:*guardduty:*honeycode:*inspector:*inspector2:*inspector2-telemetry:*inspector-scan:*ivs:*ivschat:*kendra:*kendra-ranking:*cassandra:*kinesisanalytics:*kinesisanalytics:*kinesis:*firehose:*kinesisvideo:*lex:*lex:*lightsail:*geo:*geo-maps:*geo-places:*geo-routes:*lookoutequipment:*lookoutmetrics:*lookoutvision:*machinelearning:*macie2:*managedblockchain:*managedblockchain-query:*grafana:*aps:*kafka:*kafkaconnect:*airflow:*mechanicalturk:*memorydb:*ec2messages:*ssmmessages:*mobileanalytics:*monitron:*mq:*neptune-db:*neptune-graph:*nimble:*nova-act:*one:*opensearch:*osis:*aoss:*es:*personalize:*mobiletargeting:*ses:*sms-voice:*polly:*q:*qbusiness:*qapps:*qdeveloper:*wisdom:*qldb:*quicksight:*rds:*rds-data:*rds-db:*redshift:*redshift-data:*redshift-serverless:*rekognition:*tag:*rhelkb:*route53:*route53domains:*route53profiles:*route53-recovery-cluster:*route53-recovery-control-config:*route53-recovery-readiness:*route53resolver:*s3:*s3express:*glacier:*s3-object-lambda:*s3-outposts:*s3tables:*s3vectors:*sagemaker:*sagemaker-data-science-assistant:*sagemaker-geospatial:*sagemaker-unified-studio-mcp:*sagemaker-mlflow:*securitylake:*ses:*ses:*ses:*swf:*sdb:*sns:*sqs:*textract:*timestream:*timestream-influxdb:*transcribe:*translate:*verifiedpermissions:*vpc-lattice:*vpc-lattice-svcs:*workdocs:*worklink:*workmail:*workmailmessageflow:*workspaces:*wam:*workspaces-web:*thinclient:*mediaimport:*kafka-cluster:*arsenal:*account:*action-recommendations:*activate:*amplify:*amplifybackend:*amplifyuibuilder:*appmesh:*appmesh-preview:*apprunner:*appstudio:*a2c:*appconfig:*appfabric:*application-autoscaling:*discovery:*mgn:*application-transformation:*appsync:*artifact:*auditmanager:*autoscaling-plans:*b2bi:*backup:*backup-gateway:*backup-search:*backup-storage:*batch:*billing:*bcm-dashboards:*bcm-data-exports:*bcm-pricing-calculator:*bcm-recommended-actions:*billingconductor:*aws-portal:*budgets:*bugbust:*acm:*chatbot:*cleanrooms:*cleanrooms-ml:*cloudformation:*servicediscovery:*cloud9:*cloudformation:*cloudhsm:*cloudshell:*cloudtrail:*cloudtrail-data:*rum:*codeartifact:*codebuild:*codecommit:*codeconnections:*codedeploy:*codedeploy-commands-secure:*codepipeline:*codestar:*codestar-connections:*codestar-notifications:*compute-optimizer:*aco-automation:*config:*awsconnector:*consoleapp:*consolidatedbilling:*controlcatalog:*controltower:*cur:*ce:*cost-optimization-hub:*customer-verification:*dataexchange:*datapipeline:*dms:*datasync:*deadline:*devicefarm:*aidevops:*ts:*directconnect:*ds:*ds-data:*elasticbeanstalk:*drs:*elasticloadbalancing:*elasticloadbalancing:*elemental-appliances-software:*elemental-activations:*elemental-inference:*mediaconnect:*mediaconvert:*medialive:*mediapackage:*mediapackagev2:*mediapackage-vod:*mediastore:*mediatailor:*elemental-support-cases:*elemental-support-content:*sms-voice:*social-messaging:*entityresolution:*fis:*fms:*freetier:*globalaccelerator:*glue:*databrew:*groundstation:*health:*medical-imaging:*healthlake:*omics:*access-analyzer:*sso:*sso-directory:*sso-oauth:*iam:*rolesanywhere:*identitystore:*identitystore-auth:*identity-sync:*importexport:*invoicing:*iot:*iotanalytics:*iotdeviceadvisor:*iot-device-tester:*iotevents:*iotfleethub:*iotfleetwise:*greengrass:*greengrass:*iotjobsdata:*iotmanagedintegrations:*iotsitewise:*iottwinmaker:*iotwireless:*iq:*iq-permission:*kms:*lakeformation:*lambda:*launchwizard:*license-manager:*license-manager-linux-subscriptions:*license-manager-user-subscriptions:*apptest:*m2:*aws-marketplace:*aws-marketplace:*marketplacecommerceanalytics:*aws-marketplace:*aws-marketplace:*aws-marketplace:*aws-marketplace:*aws-marketplace-management:*aws-marketplace:*aws-marketplace:*aws-marketplace:*aws-marketplace:*aws-marketplace:*vendor-insights:*aws-mcp:*serviceextract:*mapcredits:*mgh:*migrationhub-orchestrator:*refactor-spaces:*migrationhub-strategy:*airflow-serverless:*network-firewall:*networkmanager:*networkmanager-chat:*opsworks:*opsworks-cm:*organizations:*outposts:*panorama:*pcs:*partnercentral:*partnercentral-account-management:*payment-cryptography:*payments:*pi:*pricing:*pricingplanmanager:*pca-connector-ad:*pca-connector-scep:*acm-pca:*vpce:*proton:*purchase-orders:*rbin:*repostspace:*resiliencehub:*ram:*resource-explorer-2:*resource-groups:*robomaker:*route53globalresolver:*rtbfabric:*savingsplans:*secretsmanager:*securityagent:*securityhub:*security-ir:*sts:*sms:*serverlessrepo:*odb:*servicecatalog:*uxc:*private-networks:*shield:*network-security-director:*signer:*signin:*simspaceweaver:*snow-device-management:*snowball:*sqlworkbench:*states:*storagegateway:*scn:*support:*supportapp:*support-console:*supportplans:*sustainability:*ssm:*ssm-sap:*ssm-guiconnect:*ssm-incidents:*ssm-contacts:*ssm-quicksetup:*tax:*tnb:*tiros:*transfer:*transform:*transform-custom:*trustedadvisor:*notifications:*notifications-contacts:*user-subscriptions:*verified-access:*waf:*waf-regional:*wafv2:*wellarchitected:*wickr:*workspaces-instances:*xray:*dbqms:*mpa:*networkflowmonitor:*servicequotas:*resource-explorer:*