Turbot Guardrails Hub 
Hub
  • Mods
  • Policy Packs
  • Docs
  • Home
ModsPolicy PacksDocsHome
Mods
AWS
  • AWS/Owner
  • AWS/Admin
  • AWS/Metadata
  • AWS/ACM/Admin
  • AWS/ACM/Operator
  • AWS/ACM/ReadOnly
  • AWS/ACM/Metadata
  • AWS/Amplify/Admin
  • AWS/Amplify/Operator
  • AWS/Amplify/Metadata
  • AWS/API Gateway/Admin
  • AWS/API Gateway/Operator
  • AWS/API Gateway/Metadata
  • AWS/AppConfig/Admin
  • AWS/AppConfig/Operator
  • AWS/AppConfig/Metadata
  • AWS/AppFabric/Admin
  • AWS/AppFabric/Operator
  • AWS/AppFabric/Metadata
  • AWS/AppFlow/Admin
  • AWS/AppFlow/Operator
  • AWS/AppFlow/Metadata
  • AWS/App Mesh/Admin
  • AWS/App Mesh/Operator
  • AWS/App Mesh/Metadata
  • AWS/AppStream/Admin
  • AWS/AppStream/Operator
  • AWS/AppStream/Metadata
  • AWS/AppSync/Admin
  • AWS/AppSync/Metadata
  • AWS/Artifact/Admin
  • AWS/Athena/Admin
  • AWS/Athena/Operator
  • AWS/Athena/Metadata
  • AWS/Audit Manager/Admin
  • AWS/Audit Manager/Operator
  • AWS/Audit Manager/Metadata
  • AWS/Backup/Admin
  • AWS/Backup/Operator
  • AWS/Backup/Metadata
  • AWS/Batch/Admin
  • AWS/Batch/Operator
  • AWS/Batch/Metadata
  • AWS/Bedrock/Admin
  • AWS/Bedrock/Operator
  • AWS/Bedrock/Metadata
  • AWS/Bedrock AgentCore/Owner
  • AWS/Bedrock AgentCore/Admin
  • AWS/Bedrock AgentCore/Operator
  • AWS/Bedrock AgentCore/Metadata
  • AWS/Billing/Owner
  • AWS/Billing/Admin
  • AWS/Billing/Operator
  • AWS/Billing/Metadata
  • AWS/Braket/Admin
  • AWS/Braket/Operator
  • AWS/Braket/Metadata
  • AWS/Chatbot/Admin
  • AWS/Chatbot/Metadata
  • AWS/Chime/Owner
  • AWS/Chime/Admin
  • AWS/Chime/Metadata
  • AWS/CleanRooms/Admin
  • AWS/CleanRooms/Operator
  • AWS/CleanRooms/Metadata
  • AWS/Cloud9/Admin
  • AWS/Cloud9/Metadata
  • AWS/Cloud Directory/Admin
  • AWS/Cloud Directory/Operator
  • AWS/Cloud Directory/ReadOnly
  • AWS/Cloud Directory/Metadata
  • AWS/CloudFormation/Admin
  • AWS/CloudFormation/Operator
  • AWS/CloudFormation/Metadata
  • AWS/CloudFront/Admin
  • AWS/CloudFront/Operator
  • AWS/CloudFront/Metadata
  • AWS/CloudHSM/Admin
  • AWS/CloudHSM/Operator
  • AWS/CloudHSM/Metadata
  • AWS/Cloud Map/Admin
  • AWS/Cloud Map/Operator
  • AWS/Cloud Map/Metadata
  • AWS/CloudSearch/Admin
  • AWS/CloudSearch/Operator
  • AWS/CloudSearch/ReadOnly
  • AWS/CloudSearch/Metadata
  • AWS/CloudShell/Admin
  • AWS/CloudShell/Metadata
  • AWS/CloudTrail/Admin
  • AWS/CloudTrail/Operator
  • AWS/CloudTrail/Metadata
  • AWS/CloudWatch/Operator
  • AWS/CloudWatch/Metadata
  • AWS/CodeArtifact/Admin
  • AWS/CodeArtifact/Operator
  • AWS/CodeArtifact/Metadata
  • AWS/CodeBuild/Admin
  • AWS/CodeBuild/Operator
  • AWS/CodeBuild/ReadOnly
  • AWS/CodeBuild/Metadata
  • AWS/CodeCommit/Admin
  • AWS/CodeCommit/Operator
  • AWS/CodeCommit/ReadOnly
  • AWS/CodeCommit/Metadata
  • AWS/CodeDeploy/Admin
  • AWS/CodeDeploy/Operator
  • AWS/CodeDeploy/Metadata
  • AWS/CodePipeline/Admin
  • AWS/CodePipeline/Operator
  • AWS/CodePipeline/Metadata
  • AWS/CodeStar/Admin
  • AWS/CodeStar/Operator
  • AWS/CodeStar/Metadata
  • AWS/CodeWhisperer/Admin
  • AWS/CodeWhisperer/Operator
  • AWS/CodeWhisperer/Metadata
  • AWS/Cognito/Admin
  • AWS/Cognito/Operator
  • AWS/Cognito/ReadOnly
  • AWS/Cognito/Metadata
  • AWS/Comprehend/Admin
  • AWS/Comprehend/Operator
  • AWS/Comprehend/Metadata
  • AWS/Compute Optimizer/Admin
  • AWS/Compute Optimizer/Metadata
  • AWS/Config/Admin
  • AWS/Config/Operator
  • AWS/Config/Metadata
  • AWS/Connect/Admin
  • AWS/Connect/Operator
  • AWS/Connect/Metadata
  • AWS/Control Tower/Admin
  • AWS/Control Tower/Operator
  • AWS/Control Tower/Metadata
  • AWS/Data Pipeline/Admin
  • AWS/Data Pipeline/Operator
  • AWS/Data Pipeline/Metadata
  • AWS/DataSync/Admin
  • AWS/DataSync/Operator
  • AWS/DataSync/Metadata
  • AWS/DAX/Admin
  • AWS/DAX/Operator
  • AWS/DAX/Metadata
  • AWS/Device Farm/Admin
  • AWS/Device Farm/Operator
  • AWS/Device Farm/Metadata
  • AWS/Direct Connect/Admin
  • AWS/Direct Connect/Operator
  • AWS/Direct Connect/Metadata
  • AWS/Directory Service/Admin
  • AWS/Directory Service/Operator
  • AWS/Directory Service/Metadata
  • AWS/DMS/Admin
  • AWS/DMS/Operator
  • AWS/DMS/Metadata
  • AWS/DynamoDB/Owner
  • AWS/DynamoDB/Admin
  • AWS/DynamoDB/Operator
  • AWS/DynamoDB/ReadOnly
  • AWS/DynamoDB/Metadata
  • AWS/EC2/Owner
  • AWS/EC2/Admin
  • AWS/EC2/Operator
  • AWS/EC2/Metadata
  • AWS/EC2 Image Builder/Admin
  • AWS/EC2 Image Builder/Operator
  • AWS/EC2 Image Builder/Metadata
  • AWS/ECR/Owner
  • AWS/ECR/Admin
  • AWS/ECR/Operator
  • AWS/ECR/ReadOnly
  • AWS/ECR/Metadata
  • AWS/ECS/Admin
  • AWS/ECS/Operator
  • AWS/ECS/Metadata
  • AWS/EFS/Admin
  • AWS/EFS/Operator
  • AWS/EFS/Metadata
  • AWS/EKS/Admin
  • AWS/EKS/Operator
  • AWS/EKS/Metadata
  • AWS/ElastiCache/Owner
  • AWS/ElastiCache/Admin
  • AWS/ElastiCache/Operator
  • AWS/ElastiCache/Metadata
  • AWS/Elastic Beanstalk/Admin
  • AWS/Elastic Beanstalk/Operator
  • AWS/Elastic Beanstalk/Metadata
  • AWS/Elastic Inference/Admin
  • AWS/Elastic Inference/Operator
  • AWS/Elastic Inference/Metadata
  • AWS/Elasticsearch/Owner
  • AWS/Elasticsearch/Admin
  • AWS/Elasticsearch/Operator
  • AWS/Elasticsearch/ReadOnly
  • AWS/Elasticsearch/Metadata
  • AWS/Elastic Transcoder/Admin
  • AWS/Elastic Transcoder/Operator
  • AWS/Elastic Transcoder/ReadOnly
  • AWS/Elastic Transcoder/Metadata
  • AWS/EMR/Admin
  • AWS/EMR/Operator
  • AWS/EMR/Metadata
  • AWS/EventBridge Pipes/Admin
  • AWS/EventBridge Pipes/Operator
  • AWS/EventBridge Pipes/Metadata
  • AWS/EventBridge Scheduler/Admin
  • AWS/EventBridge Scheduler/Operator
  • AWS/EventBridge Scheduler/Metadata
  • AWS/Events/Admin
  • AWS/Events/Operator
  • AWS/Events/Metadata
  • AWS/Claude Platform/Admin
  • AWS/Claude Platform/Operator
  • AWS/Claude Platform/Metadata
  • AWS/FMS/Admin
  • AWS/FMS/Operator
  • AWS/FMS/Metadata
  • AWS/FSx/Admin
  • AWS/FSx/Metadata
  • AWS/GameLift/Admin
  • AWS/GameLift/Operator
  • AWS/GameLift/ReadOnly
  • AWS/GameLift/Metadata
  • AWS/Glacier/Admin
  • AWS/Glacier/Operator
  • AWS/Glacier/Metadata
  • AWS/Global Accelerator/Admin
  • AWS/Global Accelerator/Operator
  • AWS/Global Accelerator/Metadata
  • AWS/Glue/Admin
  • AWS/Glue/Operator
  • AWS/Glue/Metadata
  • AWS/Glue DataBrew/Admin
  • AWS/Glue DataBrew/Operator
  • AWS/Glue DataBrew/Metadata
  • AWS/Greengrass/Admin
  • AWS/Greengrass/Metadata
  • AWS/GuardDuty/Admin
  • AWS/GuardDuty/ReadOnly
  • AWS/GuardDuty/Metadata
  • AWS/Health/Metadata
  • AWS/IAM/Owner
  • AWS/IAM/Operator
  • AWS/IAM/Metadata
  • AWS/Inspector/Admin
  • AWS/Inspector/Operator
  • AWS/Inspector/Metadata
  • AWS/IoT/Admin
  • AWS/IoT/Operator
  • AWS/IoT/Metadata
  • AWS/IoT 1-Click/Admin
  • AWS/IoT 1-Click/Operator
  • AWS/IoT 1-Click/Metadata
  • AWS/IoT Analytics/Admin
  • AWS/IoT Analytics/Operator
  • AWS/IoT Analytics/Metadata
  • AWS/IoT Events/Admin
  • AWS/IoT Events/Operator
  • AWS/IoT Events/Metadata
  • AWS/IoT SiteWise/Admin
  • AWS/IoT SiteWise/Operator
  • AWS/IoT SiteWise/Metadata
  • AWS/IoT Things Graph/Admin
  • AWS/IoT Things Graph/Operator
  • AWS/IoT Things Graph/Metadata
  • AWS/Kendra/Admin
  • AWS/Kendra/Operator
  • AWS/Kendra/Metadata
  • AWS/Kinesis/Admin
  • AWS/Kinesis/Operator
  • AWS/Kinesis/ReadOnly
  • AWS/Kinesis/Metadata
  • AWS/KMS/Admin
  • AWS/KMS/Operator
  • AWS/KMS/Metadata
  • AWS/Lake Formation/Admin
  • AWS/Lake Formation/Operator
  • AWS/Lake Formation/Metadata
  • AWS/Lambda/Admin
  • AWS/Lambda/Operator
  • AWS/Lambda/ReadOnly
  • AWS/Lambda/Metadata
  • AWS/Lex/Admin
  • AWS/Lex/Operator
  • AWS/Lex/ReadOnly
  • AWS/Lex/Metadata
  • AWS/Lightsail/Admin
  • AWS/Lightsail/Operator
  • AWS/Lightsail/ReadOnly
  • AWS/Lightsail/Metadata
  • AWS/Location/Admin
  • AWS/Location/Operator
  • AWS/Location/Metadata
  • AWS/Logs/Admin
  • AWS/Logs/Operator
  • AWS/Logs/ReadOnly
  • AWS/Logs/Metadata
  • AWS/Machine Learning/Admin
  • AWS/Machine Learning/Operator
  • AWS/Machine Learning/ReadOnly
  • AWS/Machine Learning/Metadata
  • AWS/Macie/Admin
  • AWS/Macie/Operator
  • AWS/Macie/Metadata
  • AWS/MediaConnect/Admin
  • AWS/MediaConnect/Operator
  • AWS/MediaConnect/Metadata
  • AWS/MediaConvert/Admin
  • AWS/MediaConvert/Operator
  • AWS/MediaConvert/Metadata
  • AWS/MediaLive/Admin
  • AWS/MediaLive/Operator
  • AWS/MediaLive/Metadata
  • AWS/MediaPackage/Admin
  • AWS/MediaPackage/Metadata
  • AWS/MediaStore/Admin
  • AWS/MediaStore/Metadata
  • AWS/MediaTailor/Admin
  • AWS/MediaTailor/Metadata
  • AWS/Amazon MQ/Admin
  • AWS/Amazon MQ/Operator
  • AWS/Amazon MQ/Metadata
  • AWS/MSK/Admin
  • AWS/MSK/Operator
  • AWS/MSK/Metadata
  • AWS/MSK Connect/Admin
  • AWS/MSK Connect/Operator
  • AWS/MSK Connect/Metadata
  • AWS/MWAA/Admin
  • AWS/MWAA/Operator
  • AWS/MWAA/Metadata
  • AWS/Omics/Admin
  • AWS/Omics/Operator
  • AWS/Omics/Metadata
  • AWS/OpenSearch/Admin
  • AWS/OpenSearch/Operator
  • AWS/OpenSearch/Metadata
  • AWS/Organizations/Metadata
  • AWS/Outposts/Admin
  • AWS/Outposts/Metadata
  • AWS/Polly/Admin
  • AWS/Polly/Operator
  • AWS/Polly/ReadOnly
  • AWS/Polly/Metadata
  • AWS/QLDB/Admin
  • AWS/QLDB/Operator
  • AWS/QLDB/Metadata
  • AWS/QuickSight/Admin
  • AWS/QuickSight/Operator
  • AWS/QuickSight/Metadata
  • AWS/Resource Access Manager/Admin
  • AWS/Resource Access Manager/Operator
  • AWS/Resource Access Manager/Metadata
  • AWS/RDS/Owner
  • AWS/RDS/Admin
  • AWS/RDS/Operator
  • AWS/RDS/ReadOnly
  • AWS/RDS/Metadata
  • AWS/Redshift/Owner
  • AWS/Redshift/Admin
  • AWS/Redshift/Operator
  • AWS/Redshift/Metadata
  • AWS/Redshift Serverless/Admin
  • AWS/Redshift Serverless/Operator
  • AWS/Redshift Serverless/Metadata
  • AWS/Rekognition/Operator
  • AWS/Rekognition/Metadata
  • AWS/Resource Groups/Admin
  • AWS/Resource Groups/Operator
  • AWS/Resource Groups/Metadata
  • AWS/RoboMaker/Admin
  • AWS/RoboMaker/Operator
  • AWS/RoboMaker/Metadata
  • AWS/Route 53/Admin
  • AWS/Route 53/Metadata
  • AWS/Route 53 Domains/Admin
  • AWS/Route 53 Domains/Metadata
  • AWS/Route 53 Recovery Control Config/Admin
  • AWS/Route 53 Recovery Control Config/Metadata
  • AWS/Route 53 Recovery Readiness/Admin
  • AWS/Route 53 Recovery Readiness/Metadata
  • AWS/Route 53 Resolver/Admin
  • AWS/Route 53 Resolver/Operator
  • AWS/Route 53 Resolver/Metadata
  • AWS/S3/Admin
  • AWS/S3/Operator
  • AWS/S3/ReadOnly
  • AWS/S3/Metadata
  • AWS/S3 Table/Admin
  • AWS/S3 Table/Metadata
  • AWS/SageMaker/Admin
  • AWS/SageMaker/Operator
  • AWS/SageMaker/Metadata
  • AWS/Savings Plans/Admin
  • AWS/Savings Plans/Operator
  • AWS/Savings Plans/Metadata
  • AWS/Scheduler/Admin
  • AWS/Scheduler/Operator
  • AWS/Scheduler/Metadata
  • AWS/Secrets Manager/Admin
  • AWS/Secrets Manager/Operator
  • AWS/Secrets Manager/Metadata
  • AWS/Security Hub/Admin
  • AWS/Security Hub/Operator
  • AWS/Security Hub/Metadata
  • AWS/Serverless Application Repository/Admin
  • AWS/Serverless Application Repository/Operator
  • AWS/Serverless Application Repository/Metadata
  • AWS/Server Migration Service/Admin
  • AWS/Server Migration Service/Operator
  • AWS/Server Migration Service/Metadata
  • AWS/Service Catalog/Admin
  • AWS/Service Catalog/Operator
  • AWS/Service Catalog/Metadata
  • AWS/Service Quotas/Admin
  • AWS/Service Quotas/Operator
  • AWS/Service Quotas/Metadata
  • AWS/SES/Admin
  • AWS/SES/Operator
  • AWS/SES/Metadata
  • AWS/Shield/Admin
  • AWS/Shield/Metadata
  • AWS/Signer/Admin
  • AWS/Signer/Operator
  • AWS/Signer/Metadata
  • AWS/Simple DB/Admin
  • AWS/Simple DB/Operator
  • AWS/Simple DB/ReadOnly
  • AWS/Simple DB/Metadata
  • AWS/Snowball/Admin
  • AWS/Snowball/ReadOnly
  • AWS/Snowball/Metadata
  • AWS/SNS/Admin
  • AWS/SNS/Operator
  • AWS/SNS/Metadata
  • AWS/SQS/Admin
  • AWS/SQS/Operator
  • AWS/SQS/ReadOnly
  • AWS/SQS/Metadata
  • AWS/SSM/Admin
  • AWS/SSM/Operator
  • AWS/SSM/ReadOnly
  • AWS/SSM/Metadata
  • AWS/Step Functions/Admin
  • AWS/Step Functions/Operator
  • AWS/Step Functions/ReadOnly
  • AWS/Step Functions/Metadata
  • AWS/Storage Gateway/Admin
  • AWS/Storage Gateway/Operator
  • AWS/Storage Gateway/Metadata
  • AWS/Support/Admin
  • AWS/Support/Operator
  • AWS/Support/Metadata
  • AWS/SWF/Admin
  • AWS/SWF/Operator
  • AWS/SWF/Metadata
  • AWS/Tagging/Admin
  • AWS/Tagging/Operator
  • AWS/Tagging/Metadata
  • AWS/Textract/Admin
  • AWS/Textract/ReadOnly
  • AWS/Textract/Metadata
  • AWS/Transcribe/Admin
  • AWS/Transcribe/ReadOnly
  • AWS/Transcribe/Metadata
  • AWS/Transfer for SFTP/Admin
  • AWS/Transfer for SFTP/Operator
  • AWS/Transfer for SFTP/Metadata
  • AWS/Translate/Admin
  • AWS/Translate/Metadata
  • AWS/Trusted Advisor/Admin
  • AWS/Trusted Advisor/Metadata
  • AWS/VPC/Admin
  • AWS/VPC/Operator
  • AWS/VPC/Metadata
  • AWS/VPC Lattice/Admin
  • AWS/VPC Lattice/Operator
  • AWS/VPC Lattice/Metadata
  • AWS/WAF/Admin
  • AWS/WAF/Operator
  • AWS/WAF/ReadOnly
  • AWS/WAF/Metadata
  • AWS/WAF Regional/Admin
  • AWS/WAF Regional/Operator
  • AWS/WAF Regional/ReadOnly
  • AWS/WAF Regional/Metadata
  • AWS/Well-Architected Tool/Admin
  • AWS/Well-Architected Tool/Operator
  • AWS/Well-Architected Tool/Metadata
  • AWS/WorkDocs/Admin
  • AWS/WorkDocs/Operator
  • AWS/WorkDocs/Metadata
  • AWS/WorkSpaces/Admin
  • AWS/WorkSpaces/Operator
  • AWS/WorkSpaces/Metadata
  • AWS/X-Ray/Admin
  • AWS/X-Ray/Metadata

IAM Role: AWS/EC2/Admin

PermissionGrant
application-autoscaling:DeleteScalingPolicyAdmin
application-autoscaling:DeleteScheduledActionAdmin
application-autoscaling:PutScalingPolicyAdmin
application-autoscaling:PutScheduledActionAdmin
autoscaling-plans:CreateScalingPlanAdmin
autoscaling-plans:DeleteScalingPlanAdmin
autoscaling:DeleteWarmPoolAdmin
autoscaling:PutWarmPoolAdmin
aws-marketplace:BatchMeterUsageAdmin
aws-marketplace:MeterUsageAdmin
aws-marketplace:ResolveCustomerAdmin
ec2:AcceptAddressTransferAdmin
ec2:AcceptReservedInstancesExchangeQuoteAdmin
ec2:AllocateAddressAdmin
ec2:AllocateHostsAdmin
ec2:AssignIpv6AddressesAdmin
ec2:AssignPrivateIpAddressesAdmin
ec2:AssignPrivateNatGatewayAddressAdmin
ec2:AssociateAddressAdmin
ec2:AssociateEnclaveCertificateIamRoleAdmin
ec2:AssociateIamInstanceProfileAdmin
ec2:AssociateInstanceEventWindowAdmin
ec2:AssociateIpamByoasnAdmin
ec2:AssociateIpamResourceDiscoveryAdmin
ec2:AssociateNatGatewayAddressAdmin
ec2:AssociateTransitGatewayPolicyTableAdmin
ec2:AssociateTrunkInterfaceAdmin
ec2:AssociateVerifiedAccessInstanceWebAclAdmin
ec2:AttachNetworkInterfaceAdmin
ec2:AttachVerifiedAccessTrustProviderAdmin
ec2:AttachVolumeAdmin
ec2:BidEvictedEventAdmin
ec2:CancelCapacityReservationAdmin
ec2:CancelCapacityReservationFleetsAdmin
ec2:CancelReservedInstancesListingAdmin
ec2:CancelSpotFleetRequestsAdmin
ec2:CancelSpotInstanceRequestsAdmin
ec2:ConfirmProductInstanceAdmin
ec2:CopyFpgaImageAdmin
ec2:CreateCapacityReservationAdmin
ec2:CreateCapacityReservationFleetAdmin
ec2:CreateCoipCidrAdmin
ec2:CreateCoipPoolAdmin
ec2:CreateCoipPoolPermissionAdmin
ec2:CreateFleetAdmin
ec2:CreateInstanceConnectEndpointAdmin
ec2:CreateInstanceEventWindowAdmin
ec2:CreateIpamResourceDiscoveryAdmin
ec2:CreateKeyPairAdmin
ec2:CreateLaunchTemplateAdmin
ec2:CreateLaunchTemplateVersionAdmin
ec2:CreateLocalGatewayRouteTableAdmin
ec2:CreateLocalGatewayRouteTablePermissionAdmin
ec2:CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociationAdmin
ec2:CreateManagedPrefixListAdmin
ec2:CreateNetworkInterfaceAdmin
ec2:CreateNetworkInterfacePermissionAdmin
ec2:CreatePlacementGroupAdmin
ec2:CreateReplaceRootVolumeTaskAdmin
ec2:CreateReservedInstancesListingAdmin
ec2:CreateRestoreImageTaskAdmin
ec2:CreateSpotDatafeedSubscriptionAdmin
ec2:CreateStoreImageTaskAdmin
ec2:CreateTransitGatewayPolicyTableAdmin
ec2:CreateTransitGatewayRouteTableAnnouncementAdmin
ec2:CreateVerifiedAccessEndpointAdmin
ec2:CreateVerifiedAccessGroupAdmin
ec2:CreateVerifiedAccessInstanceAdmin
ec2:CreateVerifiedAccessTrustProviderAdmin
ec2:CreateVolumeAdmin
ec2:DeleteCoipCidrAdmin
ec2:DeleteCoipPoolAdmin
ec2:DeleteCoipPoolPermissionAdmin
ec2:DeleteFleetsAdmin
ec2:DeleteFpgaImageAdmin
ec2:DeleteInstanceConnectEndpointAdmin
ec2:DeleteInstanceEventWindowAdmin
ec2:DeleteIpamResourceDiscoveryAdmin
ec2:DeleteKeyPairAdmin
ec2:DeleteLaunchTemplateAdmin
ec2:DeleteLaunchTemplateVersionsAdmin
ec2:DeleteLocalGatewayRouteTableAdmin
ec2:DeleteLocalGatewayRouteTablePermissionAdmin
ec2:DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociationAdmin
ec2:DeleteManagedPrefixListAdmin
ec2:DeleteNetworkInterfaceAdmin
ec2:DeleteNetworkInterfacePermissionAdmin
ec2:DeletePlacementGroupAdmin
ec2:DeleteQueuedReservedInstancesAdmin
ec2:DeleteResourcePolicyAdmin
ec2:DeleteSnapshotAdmin
ec2:DeleteSpotDatafeedSubscriptionAdmin
ec2:DeleteTransitGatewayPolicyTableAdmin
ec2:DeleteTransitGatewayRouteTableAnnouncementAdmin
ec2:DeleteVerifiedAccessEndpointAdmin
ec2:DeleteVerifiedAccessGroupAdmin
ec2:DeleteVerifiedAccessInstanceAdmin
ec2:DeleteVerifiedAccessTrustProviderAdmin
ec2:DeleteVolumeAdmin
ec2:DeprovisionIpamByoasnAdmin
ec2:DeregisterInstanceEventNotificationAttributesAdmin
ec2:DetachClassicLinkVpcAdmin
ec2:DetachNetworkInterfaceAdmin
ec2:DetachVerifiedAccessTrustProviderAdmin
ec2:DetachVolumeAdmin
ec2:DisableAddressTransferAdmin
ec2:DisableAwsNetworkPerformanceMetricSubscriptionAdmin
ec2:DisableEbsEncryptionByDefaultAdmin
ec2:DisableFastLaunchAdmin
ec2:DisableFastSnapshotRestoresAdmin
ec2:DisableImageAdmin
ec2:DisableImageBlockPublicAccessAdmin
ec2:DisableImageDeregistrationProtectionAdmin
ec2:DisableImageDeprecationAdmin
ec2:DisableSerialConsoleAccessAdmin
ec2:DisableSnapshotBlockPublicAccessAdmin
ec2:DisassociateAddressAdmin
ec2:DisassociateEnclaveCertificateIamRoleAdmin
ec2:DisassociateIamInstanceProfileAdmin
ec2:DisassociateInstanceEventWindowAdmin
ec2:DisassociateIpamByoasnAdmin
ec2:DisassociateIpamResourceDiscoveryAdmin
ec2:DisassociateNatGatewayAddressAdmin
ec2:DisassociateTransitGatewayPolicyTableAdmin
ec2:DisassociateTrunkInterfaceAdmin
ec2:DisassociateVerifiedAccessInstanceWebAclAdmin
ec2:EnableAddressTransferAdmin
ec2:EnableAwsNetworkPerformanceMetricSubscriptionAdmin
ec2:EnableEbsEncryptionByDefaultAdmin
ec2:EnableFastLaunchAdmin
ec2:EnableFastSnapshotRestoresAdmin
ec2:EnableImageAdmin
ec2:EnableImageBlockPublicAccessAdmin
ec2:EnableImageDeregistrationProtectionAdmin
ec2:EnableImageDeprecationAdmin
ec2:EnableReachabilityAnalyzerOrganizationSharingAdmin
ec2:EnableSerialConsoleAccessAdmin
ec2:EnableSnapshotBlockPublicAccessAdmin
ec2:EnableVolumeIOAdmin
ec2:GetPasswordDataAdmin
ec2:ImportKeyPairAdmin
ec2:LockSnapshotAdmin
ec2:ModifyAvailabilityZoneGroupAdmin
ec2:ModifyCapacityReservationAdmin
ec2:ModifyCapacityReservationFleetAdmin
ec2:ModifyDefaultCreditSpecificationAdmin
ec2:ModifyEbsDefaultKmsKeyIdAdmin
ec2:ModifyFleetAdmin
ec2:ModifyFpgaImageAttributeAdmin
ec2:ModifyHostsAdmin
ec2:ModifyIdentityIdFormatAdmin
ec2:ModifyIdFormatAdmin
ec2:ModifyInstanceAttributeAdmin
ec2:ModifyInstanceCapacityReservationAttributesAdmin
ec2:ModifyInstanceCreditSpecificationAdmin
ec2:ModifyInstanceEventStartTimeAdmin
ec2:ModifyInstanceEventWindowAdmin
ec2:ModifyInstanceMaintenanceOptionsAdmin
ec2:ModifyInstanceMetadataDefaultsAdmin
ec2:ModifyInstanceMetadataOptionsAdmin
ec2:ModifyInstancePlacementAdmin
ec2:ModifyIpamResourceDiscoveryAdmin
ec2:ModifyLaunchTemplateAdmin
ec2:ModifyLocalGatewayRouteAdmin
ec2:ModifyNetworkInterfaceAttributeAdmin
ec2:ModifyPrivateDnsNameOptionsAdmin
ec2:ModifyReservedInstancesAdmin
ec2:ModifySnapshotAttributeAdmin
ec2:ModifySnapshotTierAdmin
ec2:ModifySpotFleetRequestAdmin
ec2:ModifyVerifiedAccessEndpointAdmin
ec2:ModifyVerifiedAccessEndpointPolicyAdmin
ec2:ModifyVerifiedAccessGroupAdmin
ec2:ModifyVerifiedAccessGroupPolicyAdmin
ec2:ModifyVerifiedAccessInstanceAdmin
ec2:ModifyVerifiedAccessInstanceLoggingConfigurationAdmin
ec2:ModifyVerifiedAccessTrustProviderAdmin
ec2:ModifyVolumeAdmin
ec2:ModifyVolumeAttributeAdmin
ec2:ModifyVpcEndpointServicePayerResponsibilityAdmin
ec2:MonitorInstancesAdmin
ec2:MoveAddressToVpcAdmin
ec2:PauseVolumeIOAdmin
ec2:ProvisionIpamByoasnAdmin
ec2:PurchaseCapacityBlockAdmin
ec2:PurchaseHostReservationAdmin
ec2:PurchaseReservedInstancesOfferingAdmin
ec2:PutResourcePolicyAdmin
ec2:RegisterInstanceEventNotificationAttributesAdmin
ec2:ReleaseAddressAdmin
ec2:ReleaseHostsAdmin
ec2:ReplaceIamInstanceProfileAssociationAdmin
ec2:RequestSpotFleetAdmin
ec2:RequestSpotInstancesAdmin
ec2:ResetEbsDefaultKmsKeyIdAdmin
ec2:ResetFpgaImageAttributeAdmin
ec2:ResetInstanceAttributeAdmin
ec2:ResetNetworkInterfaceAttributeAdmin
ec2:ResetSnapshotAttributeAdmin
ec2:RestoreAddressToClassicAdmin
ec2:RestoreImageFromRecycleBinAdmin
ec2:RestoreSnapshotFromRecycleBinAdmin
ec2:RestoreSnapshotTierAdmin
ec2:RunInstancesAdmin
ec2:RunScheduledInstancesAdmin
ec2:SendDiagnosticInterruptAdmin
ec2:SendSpotInstanceInterruptionsAdmin
ec2:TerminateInstancesAdmin
ec2:UnassignIpv6AddressesAdmin
ec2:UnassignPrivateIpAddressesAdmin
ec2:UnassignPrivateNatGatewayAddressAdmin
ec2:UnlockSnapshotAdmin
ec2:UnmonitorInstancesAdmin
elastic-inference:ConnectAdmin
elasticloadbalancing:AddListenerCertificatesAdmin
elasticloadbalancing:ApplySecurityGroupsToLoadBalancerAdmin
elasticloadbalancing:AttachLoadBalancerToSubnetsAdmin
elasticloadbalancing:ConfigureHealthCheckAdmin
elasticloadbalancing:CreateAppCookieStickinessPolicyAdmin
elasticloadbalancing:CreateLBCookieStickinessPolicyAdmin
elasticloadbalancing:CreateListenerAdmin
elasticloadbalancing:CreateLoadBalancerAdmin
elasticloadbalancing:CreateLoadBalancerListenersAdmin
elasticloadbalancing:CreateLoadBalancerListenersAdmin
elasticloadbalancing:CreateLoadBalancerPolicyAdmin
elasticloadbalancing:CreateRuleAdmin
elasticloadbalancing:CreateTargetGroupAdmin
elasticloadbalancing:DeleteListenerAdmin
elasticloadbalancing:DeleteLoadBalancerAdmin
elasticloadbalancing:DeleteLoadBalancerListenersAdmin
elasticloadbalancing:DeleteLoadBalancerPolicyAdmin
elasticloadbalancing:DeleteRuleAdmin
elasticloadbalancing:DeleteTargetGroupAdmin
elasticloadbalancing:DetachLoadBalancerFromSubnetsAdmin
elasticloadbalancing:DisableAvailabilityZonesForLoadBalancerAdmin
elasticloadbalancing:EnableAvailabilityZonesForLoadBalancerAdmin
elasticloadbalancing:ModifyListenerAdmin
elasticloadbalancing:ModifyLoadBalancerAttributesAdmin
elasticloadbalancing:ModifyRuleAdmin
elasticloadbalancing:ModifyTargetGroupAdmin
elasticloadbalancing:ModifyTargetGroupAttributesAdmin
elasticloadbalancing:RemoveListenerCertificatesAdmin
elasticloadbalancing:SetIpAddressTypeAdmin
elasticloadbalancing:SetLoadBalancerListenerSSLCertificateAdmin
elasticloadbalancing:SetLoadBalancerListenerSSLCertificateAdmin
elasticloadbalancing:SetLoadBalancerPoliciesForBackendServerAdmin
elasticloadbalancing:SetLoadBalancerPoliciesOfListenerAdmin
elasticloadbalancing:SetLoadBalancerPoliciesOfListenerAdmin
elasticloadbalancing:SetRulePrioritiesAdmin
elasticloadbalancing:SetSecurityGroupsAdmin
elasticloadbalancing:SetSubnetsAdmin
elasticloadbalancing:SetWebAclAdmin
iam:PassRoleAdmin
marketplacecommerceanalytics:GenerateDataSetAdmin
marketplacecommerceanalytics:StartSupportDataExportAdmin
application-autoscaling:DeregisterScalableTargetOperator
application-autoscaling:RegisterScalableTargetOperator
autoscaling-plans:UpdateScalingPlanOperator
autoscaling:AttachInstancesOperator
autoscaling:AttachLoadBalancersOperator
autoscaling:AttachLoadBalancerTargetGroupsOperator
autoscaling:CompleteLifecycleActionOperator
autoscaling:CreateOrUpdateTagsOperator
autoscaling:DeleteNotificationConfigurationOperator
autoscaling:DeleteTagsOperator
autoscaling:DetachInstancesOperator
autoscaling:DetachLoadBalancersOperator
autoscaling:DetachLoadBalancerTargetGroupsOperator
autoscaling:DisableMetricsCollectionOperator
autoscaling:EnableMetricsCollectionOperator
autoscaling:EnterStandbyOperator
autoscaling:ExecutePolicyOperator
autoscaling:ExitStandbyOperator
autoscaling:PutNotificationConfigurationOperator
autoscaling:RecordLifecycleActionHeartbeatOperator
autoscaling:ResumeProcessesOperator
autoscaling:SetInstanceHealthOperator
autoscaling:SetInstanceProtectionOperator
autoscaling:SuspendProcessesOperator
autoscaling:TerminateInstanceInAutoScalingGroupOperator
ec2:CopySnapshotOperator
ec2:CreateSnapshotOperator
ec2:CreateSnapshotsOperator
ec2:CreateTagsOperator
ec2:DeleteTagsOperator
ec2:ExportImageOperator
ec2:RebootInstancesOperator
ec2:ReplaceVpnTunnelOperator
ec2:ReportInstanceStatusOperator
ec2:StartInstancesOperator
ec2:StopInstancesOperator
elasticloadbalancing:AddTagsOperator
elasticloadbalancing:DeregisterInstancesFromLoadBalancerOperator
elasticloadbalancing:DeregisterTargetsOperator
elasticloadbalancing:RegisterInstancesWithLoadBalancerOperator
elasticloadbalancing:RegisterTargetsOperator
elasticloadbalancing:RemoveTagsOperator
acm:ListCertificatesMetadata
application-autoscaling:DescribeScalableTargetsMetadata
application-autoscaling:DescribeScalingActivitiesMetadata
application-autoscaling:DescribeScalingPoliciesMetadata
application-autoscaling:DescribeScheduledActionsMetadata
autoscaling-plans:DescribeScalingPlanResourcesMetadata
autoscaling-plans:DescribeScalingPlansMetadata
autoscaling-plans:GetScalingPlanResourceForecastDataMetadata
autoscaling:DescribeAccountLimitsMetadata
autoscaling:DescribeAdjustmentTypesMetadata
autoscaling:DescribeAutoScalingGroupsMetadata
autoscaling:DescribeAutoScalingInstancesMetadata
autoscaling:DescribeAutoScalingNotificationTypesMetadata
autoscaling:DescribeInstanceRefreshesMetadata
autoscaling:DescribeLaunchConfigurationsMetadata
autoscaling:DescribeLifecycleHooksMetadata
autoscaling:DescribeLifecycleHookTypesMetadata
autoscaling:DescribeLoadBalancersMetadata
autoscaling:DescribeLoadBalancerTargetGroupsMetadata
autoscaling:DescribeMetricCollectionTypesMetadata
autoscaling:DescribeNotificationConfigurationsMetadata
autoscaling:DescribePoliciesMetadata
autoscaling:DescribeScalingActivitiesMetadata
autoscaling:DescribeScalingPlanResourcesMetadata
autoscaling:DescribeScalingPlansMetadata
autoscaling:DescribeScalingProcessTypesMetadata
autoscaling:DescribeScheduledActionsMetadata
autoscaling:DescribeTagsMetadata
autoscaling:DescribeTerminationPolicyTypesMetadata
autoscaling:DescribeTriggersMetadata
autoscaling:DescribeWarmPoolMetadata
aws-marketplace:GetEntitlementsMetadata
aws-marketplace:ViewSubscriptionsMetadata
cloudwatch:DescribeAlarmHistoryMetadata
cloudwatch:DescribeAlarmsMetadata
cloudwatch:DescribeAlarmsForMetricMetadata
cloudwatch:GetMetricDataMetadata
cloudwatch:GetMetricStatisticsMetadata
cloudwatch:ListMetricsMetadata
ec2:DescribeAccountAttributesMetadata
ec2:DescribeAddressesMetadata
ec2:DescribeAddressesAttributeMetadata
ec2:DescribeAddressTransfersMetadata
ec2:DescribeAvailabilityZonesMetadata
ec2:DescribeAwsNetworkPerformanceMetricSubscriptionsMetadata
ec2:DescribeBundleTasksMetadata
ec2:DescribeCapacityBlockOfferingsMetadata
ec2:DescribeCapacityReservationFleetsMetadata
ec2:DescribeCapacityReservationsMetadata
ec2:DescribeCarrierGatewaysMetadata
ec2:DescribeClassicLinkInstancesMetadata
ec2:DescribeConversionTasksMetadata
ec2:DescribeElasticGpusMetadata
ec2:DescribeExportImageTasksMetadata
ec2:DescribeExportTasksMetadata
ec2:DescribeFastLaunchImagesMetadata
ec2:DescribeFastSnapshotRestoresMetadata
ec2:DescribeFleetHistoryMetadata
ec2:DescribeFleetInstancesMetadata
ec2:DescribeFleetsMetadata
ec2:DescribeFpgaImageAttributeMetadata
ec2:DescribeFpgaImagesMetadata
ec2:DescribeHostReservationOfferingsMetadata
ec2:DescribeHostReservationsMetadata
ec2:DescribeHostsMetadata
ec2:DescribeIamInstanceProfileAssociationsMetadata
ec2:DescribeIdentityIdFormatMetadata
ec2:DescribeIdFormatMetadata
ec2:DescribeImageAttributeMetadata
ec2:DescribeImagesMetadata
ec2:DescribeImportImageTasksMetadata
ec2:DescribeImportSnapshotTasksMetadata
ec2:DescribeInstanceAttributeMetadata
ec2:DescribeInstanceConnectEndpointsMetadata
ec2:DescribeInstanceCreditSpecificationsMetadata
ec2:DescribeInstanceEventNotificationAttributesMetadata
ec2:DescribeInstanceEventWindowsMetadata
ec2:DescribeInstancesMetadata
ec2:DescribeInstanceStatusMetadata
ec2:DescribeInstanceTopologyMetadata
ec2:DescribeInstanceTypeOfferingsMetadata
ec2:DescribeInstanceTypesMetadata
ec2:DescribeIpamByoasnMetadata
ec2:DescribeIpamResourceDiscoveriesMetadata
ec2:DescribeIpamResourceDiscoveryAssociationsMetadata
ec2:DescribeIpv6PoolsMetadata
ec2:DescribeKeyPairsMetadata
ec2:DescribeLaunchTemplatesMetadata
ec2:DescribeLaunchTemplateVersionsMetadata
ec2:DescribeLicensesMetadata
ec2:DescribeLocalGatewayRouteTablePermissionsMetadata
ec2:DescribeLockedSnapshotsMetadata
ec2:DescribeMovingAddressesMetadata
ec2:DescribeNetworkInterfaceAttributeMetadata
ec2:DescribeNetworkInterfacePermissionsMetadata
ec2:DescribeNetworkInterfacesMetadata
ec2:DescribePlacementGroupsMetadata
ec2:DescribePublicIpv4PoolsMetadata
ec2:DescribeRegionsMetadata
ec2:DescribeReplaceRootVolumeTasksMetadata
ec2:DescribeReservedInstancesMetadata
ec2:DescribeReservedInstancesListingsMetadata
ec2:DescribeReservedInstancesModificationsMetadata
ec2:DescribeReservedInstancesOfferingsMetadata
ec2:DescribeScheduledInstanceAvailabilityMetadata
ec2:DescribeScheduledInstancesMetadata
ec2:DescribeSecurityGroupReferencesMetadata
ec2:DescribeSecurityGroupsMetadata
ec2:DescribeSnapshotAttributeMetadata
ec2:DescribeSnapshotsMetadata
ec2:DescribeSnapshotTierStatusMetadata
ec2:DescribeSpotDatafeedSubscriptionMetadata
ec2:DescribeSpotFleetInstancesMetadata
ec2:DescribeSpotFleetRequestHistoryMetadata
ec2:DescribeSpotFleetRequestsMetadata
ec2:DescribeSpotInstanceRequestsMetadata
ec2:DescribeSpotPriceHistoryMetadata
ec2:DescribeStaleSecurityGroupsMetadata
ec2:DescribeStoreImageTasksMetadata
ec2:DescribeTagsMetadata
ec2:DescribeTransitGatewayPolicyTablesMetadata
ec2:DescribeTransitGatewayRouteTableAnnouncementsMetadata
ec2:DescribeVerifiedAccessEndpointsMetadata
ec2:DescribeVerifiedAccessGroupsMetadata
ec2:DescribeVerifiedAccessInstanceLoggingConfigurationsMetadata
ec2:DescribeVerifiedAccessInstancesMetadata
ec2:DescribeVerifiedAccessInstanceWebAclAssociationsMetadata
ec2:DescribeVerifiedAccessTrustProvidersMetadata
ec2:DescribeVolumeAttributeMetadata
ec2:DescribeVolumesMetadata
ec2:DescribeVolumesModificationsMetadata
ec2:DescribeVolumeStatusMetadata
ec2:GetAssociatedEnclaveCertificateIamRolesMetadata
ec2:GetAwsNetworkPerformanceDataMetadata
ec2:GetCapacityReservationUsageMetadata
ec2:GetConsoleOutputMetadata
ec2:GetConsoleScreenshotMetadata
ec2:GetDefaultCreditSpecificationMetadata
ec2:GetEbsDefaultKmsKeyIdMetadata
ec2:GetEbsEncryptionByDefaultMetadata
ec2:GetGroupsForCapacityReservationMetadata
ec2:GetHostReservationPurchasePreviewMetadata
ec2:GetImageBlockPublicAccessStateMetadata
ec2:GetInstanceTypesFromInstanceRequirementsMetadata
ec2:GetInstanceUefiDataMetadata
ec2:GetIpamDiscoveredAccountsMetadata
ec2:GetIpamDiscoveredPublicAddressesMetadata
ec2:GetIpamDiscoveredResourceCidrsMetadata
ec2:GetLaunchTemplateDataMetadata
ec2:GetReservedInstancesExchangeQuoteMetadata
ec2:GetResourcePolicyMetadata
ec2:GetSecurityGroupsForVpcMetadata
ec2:GetSerialConsoleAccessStatusMetadata
ec2:GetSnapshotBlockPublicAccessStateMetadata
ec2:GetSpotPlacementScoresMetadata
ec2:GetTransitGatewayPolicyTableAssociationsMetadata
ec2:GetTransitGatewayPolicyTableEntriesMetadata
ec2:GetVerifiedAccessEndpointPolicyMetadata
ec2:GetVerifiedAccessGroupPolicyMetadata
ec2:GetVerifiedAccessInstanceWebAclMetadata
ec2:GetVpnTunnelReplacementStatusMetadata
ec2:ListImagesInRecycleBinMetadata
ec2:ListSnapshotsInRecycleBinMetadata
elasticloadbalancing:DescribeAccountLimitsMetadata
elasticloadbalancing:DescribeInstanceHealthMetadata
elasticloadbalancing:DescribeListenerCertificatesMetadata
elasticloadbalancing:DescribeListenersMetadata
elasticloadbalancing:DescribeLoadBalancerAttributesMetadata
elasticloadbalancing:DescribeLoadBalancerPoliciesMetadata
elasticloadbalancing:DescribeLoadBalancerPolicyTypesMetadata
elasticloadbalancing:DescribeLoadBalancersMetadata
elasticloadbalancing:DescribeRulesMetadata
elasticloadbalancing:DescribeSSLPoliciesMetadata
elasticloadbalancing:DescribeTagsMetadata
elasticloadbalancing:DescribeTargetGroupAttributesMetadata
elasticloadbalancing:DescribeTargetGroupsMetadata
elasticloadbalancing:DescribeTargetHealthMetadata
health:DescribeEventAggregatesMetadata
kms:ListAliasesMetadata
Guardrails
Guardrails Hub
  • Hub
  • Docs
  • Blog
  • Changelog
Products
  • GuardrailsGuardrails
  • PipesPipes
  • SteampipeSteampipe
  • PowerpipePowerpipe
  • FlowpipeFlowpipe
  • TailpipeTailpipe
Turbot
  • Home
  • About us
  • We're hiring!
  • Contact us
Community

Our community of practitioners love to discuss cloud governance & security.

Slack logoJoin us on Slack →

System StatusLegalSecurity
Terms of UseSecurityPrivacy
182
Mods
519
Resource Types
8,948
Policies
3,489
Controls
1,929
Quick Actions
547
IAM