Mods

IAM Role: AWS/Control Tower/Operator

PermissionGrant
controltower:TagResourceOperator
controltower:UntagResourceOperator
controlcatalog:GetControlMetadata
controlcatalog:ListCommonControlsMetadata
controlcatalog:ListControlMappingsMetadata
controlcatalog:ListControlsMetadata
controlcatalog:ListDomainsMetadata
controlcatalog:ListObjectivesMetadata
controltower:DescribeAccountFactoryConfigMetadata
controltower:DescribeCoreServiceMetadata
controltower:DescribeGuardrailMetadata
controltower:DescribeGuardrailForTargetMetadata
controltower:DescribeLandingZoneConfigurationMetadata
controltower:DescribeManagedAccountMetadata
controltower:DescribeManagedOrganizationalUnitMetadata
controltower:DescribeRegisterOrganizationalUnitOperationMetadata
controltower:DescribeSingleSignOnMetadata
controltower:GetAccountInfoMetadata
controltower:GetAvailableUpdatesMetadata
controltower:GetBaselineMetadata
controltower:GetBaselineOperationMetadata
controltower:GetControlOperationMetadata
controltower:GetEnabledBaselineMetadata
controltower:GetEnabledControlMetadata
controltower:GetGuardrailComplianceStatusMetadata
controltower:GetHomeRegionMetadata
controltower:GetLandingZoneMetadata
controltower:GetLandingZoneDriftStatusMetadata
controltower:GetLandingZoneOperationMetadata
controltower:GetLandingZoneStatusMetadata
controltower:ListBaselinesMetadata
controltower:ListControlOperationsMetadata
controltower:ListDirectoryGroupsMetadata
controltower:ListDriftDetailsMetadata
controltower:ListEnabledBaselinesMetadata
controltower:ListEnabledControlsMetadata
controltower:ListEnabledGuardrailsMetadata
controltower:ListExtendGovernancePrecheckDetailsMetadata
controltower:ListExternalConfigRuleComplianceMetadata
controltower:ListGuardrailViolationsMetadata
controltower:ListGuardrailsMetadata
controltower:ListGuardrailsForTargetMetadata
controltower:ListLandingZoneOperationsMetadata
controltower:ListLandingZonesMetadata
controltower:ListManagedAccountsMetadata
controltower:ListManagedAccountsForGuardrailMetadata
controltower:ListManagedAccountsForParentMetadata
controltower:ListManagedOrganizationalUnitsMetadata
controltower:ListManagedOrganizationalUnitsForGuardrailMetadata
controltower:ListTagsForResourceMetadata
controltower:PerformPreLaunchChecksMetadata