Mods
AWS

IAM Role: AWS/CloudHSM/Admin

PermissionGrant
cloudhsm:CreateClusterAdmin
cloudhsm:CreateHapgAdmin
cloudhsm:CreateHsmAdmin
cloudhsm:CreateLunaClientAdmin
cloudhsm:DeleteBackupAdmin
cloudhsm:DeleteClusterAdmin
cloudhsm:DeleteHapgAdmin
cloudhsm:DeleteHsmAdmin
cloudhsm:DeleteLunaClientAdmin
cloudhsm:GetConfigAdmin
cloudhsm:InitializeClusterAdmin
cloudhsm:RestoreBackupAdmin
cloudhsm:AddTagsToResourceOperator
cloudhsm:CopyBackupToRegionOperator
cloudhsm:ModifyHapgOperator
cloudhsm:ModifyHsmOperator
cloudhsm:ModifyLunaClientOperator
cloudhsm:RemoveTagsFromResourceOperator
cloudhsm:TagResourceOperator
cloudhsm:UntagResourceOperator
cloudhsm:DescribeBackupsMetadata
cloudhsm:DescribeClustersMetadata
cloudhsm:DescribeHapgMetadata
cloudhsm:DescribeHsmMetadata
cloudhsm:DescribeLunaClientMetadata
cloudhsm:ListAvailableZonesMetadata
cloudhsm:ListHapgsMetadata
cloudhsm:ListHsmsMetadata
cloudhsm:ListLunaClientsMetadata
cloudhsm:ListTagsMetadata
cloudhsm:ListTagsForResourceMetadata