Mods
AWS

IAM Role: AWS/IAM/Owner

PermissionGrant
access-analyzer:ApplyArchiveRuleOwner
access-analyzer:CancelPolicyGenerationOwner
access-analyzer:CreateAccessPreviewOwner
access-analyzer:CreateAnalyzerOwner
access-analyzer:CreateArchiveRuleOwner
access-analyzer:DeleteAnalyzerOwner
access-analyzer:DeleteArchiveRuleOwner
access-analyzer:StartPolicyGenerationOwner
access-analyzer:StartResourceScanOwner
access-analyzer:UpdateArchiveRuleOwner
access-analyzer:UpdateFindingsOwner
iam:AddRoleToInstanceProfileOwner
iam:AddUserToGroupOwner
iam:AttachGroupPolicyOwner
iam:AttachRolePolicyOwner
iam:CreateAccountAliasOwner
iam:CreateGroupOwner
iam:CreateInstanceProfileOwner
iam:CreatePolicyOwner
iam:CreatePolicyVersionOwner
iam:CreateRoleOwner
iam:CreateSAMLProviderOwner
iam:CreateServiceLinkedRoleOwner
iam:CreateServiceSpecificCredentialOwner
iam:CreateVirtualMFADeviceOwner
iam:DeactivateMFADeviceOwner
iam:DeleteAccountAliasOwner
iam:DeleteAccountPasswordPolicyOwner
iam:DeleteGroupOwner
iam:DeleteGroupPolicyOwner
iam:DeleteInstanceProfileOwner
iam:DeletePolicyOwner
iam:DeletePolicyVersionOwner
iam:DeleteRoleOwner
iam:DeleteRolePermissionsBoundaryOwner
iam:DeleteRolePolicyOwner
iam:DeleteSAMLProviderOwner
iam:DeleteSSHPublicKeyOwner
iam:DeleteServerCertificateOwner
iam:DeleteServiceLinkedRoleOwner
iam:DeleteServiceSpecificCredentialOwner
iam:DeleteUserPermissionsBoundaryOwner
iam:DeleteUserPermissionsBoundaryOwner
iam:DeleteVirtualMFADeviceOwner
iam:DetachGroupPolicyOwner
iam:DetachRolePolicyOwner
iam:EnableMFADeviceOwner
iam:GenerateOrganizationsAccessReportOwner
iam:PassRoleOwner
iam:PutGroupPolicyOwner
iam:PutRolePermissionsBoundaryOwner
iam:PutRolePolicyOwner
iam:PutUserPermissionsBoundaryOwner
iam:RemoveRoleFromInstanceProfileOwner
iam:RemoveUserFromGroupOwner
iam:ResetServiceSpecificCredentialOwner
iam:ResyncMFADeviceOwner
iam:SetDefaultPolicyVersionOwner
iam:SetSecurityTokenServicePreferencesOwner
iam:UpdateAccountPasswordPolicyOwner
iam:UpdateAssumeRolePolicyOwner
iam:UpdateGroupOwner
iam:UpdateRoleOwner
iam:UpdateRoleDescriptionOwner
iam:UpdateSAMLProviderOwner
iam:UpdateSSHPublicKeyOwner
iam:UpdateServerCertificateOwner
iam:UpdateServiceSpecificCredentialOwner
iam:UploadSSHPublicKeyOwner
iam:UploadServerCertificateOwner
access-analyzer:TagResourceOperator
access-analyzer:UntagResourceOperator
access-analyzer:ValidatePolicyOperator
iam:TagInstanceProfileOperator
iam:TagMFADeviceOperator
iam:TagOpenIDConnectProviderOperator
iam:TagPolicyOperator
iam:TagRoleOperator
iam:TagSAMLProviderOperator
iam:TagServerCertificateOperator
iam:TagUserOperator
iam:UntagInstanceProfileOperator
iam:UntagMFADeviceOperator
iam:UntagOpenIDConnectProviderOperator
iam:UntagPolicyOperator
iam:UntagRoleOperator
iam:UntagSAMLProviderOperator
iam:UntagServerCertificateOperator
iam:UntagUserOperator
sts:AssumeRoleOperator
sts:AssumeRoleWithSAMLOperator
sts:AssumeRoleWithWebIdentityOperator
access-analyzer:GetAccessPreviewMetadata
access-analyzer:GetAnalyzedResourceMetadata
access-analyzer:GetAnalyzerMetadata
access-analyzer:GetArchiveRuleMetadata
access-analyzer:GetFindingMetadata
access-analyzer:GetGeneratedPolicyMetadata
access-analyzer:ListAccessPreviewFindingsMetadata
access-analyzer:ListAccessPreviewsMetadata
access-analyzer:ListAnalyzedResourcesMetadata
access-analyzer:ListAnalyzersMetadata
access-analyzer:ListArchiveRulesMetadata
access-analyzer:ListFindingsMetadata
access-analyzer:ListPolicyGenerationsMetadata
access-analyzer:ListTagsForResourceMetadata
iam:GenerateCredentialReportMetadata
iam:GenerateServiceLastAccessedDetailsMetadata
iam:GetAccessKeyLastUsedMetadata
iam:GetAccountAuthorizationDetailsMetadata
iam:GetAccountPasswordPolicyMetadata
iam:GetAccountSummaryMetadata
iam:GetContextKeysForCustomPolicyMetadata
iam:GetContextKeysForPrincipalPolicyMetadata
iam:GetCredentialReportMetadata
iam:GetGroupMetadata
iam:GetGroupPolicyMetadata
iam:GetInstanceProfileMetadata
iam:GetLoginProfileMetadata
iam:GetOpenIDConnectProviderMetadata
iam:GetOrganizationsAccessReportMetadata
iam:GetPolicyMetadata
iam:GetPolicyVersionMetadata
iam:GetRoleMetadata
iam:GetRolePolicyMetadata
iam:GetSAMLProviderMetadata
iam:GetSSHPublicKeyMetadata
iam:GetServerCertificateMetadata
iam:GetServiceLastAccessedDetailsMetadata
iam:GetServiceLastAccessedDetailsWithEntitiesMetadata
iam:GetServiceLinkedRoleDeletionStatusMetadata
iam:GetUserMetadata
iam:GetUserPolicyMetadata
iam:ListAccessKeysMetadata
iam:ListAccountAliasesMetadata
iam:ListAttachedGroupPoliciesMetadata
iam:ListAttachedRolePoliciesMetadata
iam:ListAttachedUserPoliciesMetadata
iam:ListEntitiesForPolicyMetadata
iam:ListGroupPoliciesMetadata
iam:ListGroupsMetadata
iam:ListGroupsForUserMetadata
iam:ListInstanceProfileTagsMetadata
iam:ListInstanceProfilesMetadata
iam:ListInstanceProfilesForRoleMetadata
iam:ListMFADeviceTagsMetadata
iam:ListMFADevicesMetadata
iam:ListOpenIDConnectProviderTagsMetadata
iam:ListOpenIDConnectProvidersMetadata
iam:ListPoliciesMetadata
iam:ListPoliciesGrantingServiceAccessMetadata
iam:ListPolicyTagsMetadata
iam:ListPolicyVersionsMetadata
iam:ListRolePoliciesMetadata
iam:ListRoleTagsMetadata
iam:ListRolesMetadata
iam:ListSAMLProviderTagsMetadata
iam:ListSAMLProvidersMetadata
iam:ListSSHPublicKeysMetadata
iam:ListServerCertificateTagsMetadata
iam:ListServerCertificatesMetadata
iam:ListServiceSpecificCredentialsMetadata
iam:ListSigningCertificatesMetadata
iam:ListUserPoliciesMetadata
iam:ListUserTagsMetadata
iam:ListUsersMetadata
iam:ListVirtualMFADevicesMetadata
iam:SimulateCustomPolicyMetadata
iam:SimulatePrincipalPolicyMetadata
organizations:DescribeOrganizationMetadata
sts:DecodeAuthorizationMessageMetadata