Mods
AWS

IAM Role: AWS/Macie/Metadata

PermissionGrant
kms:ListAliasesMetadata
macie2:BatchGetCustomDataIdentifiersMetadata
macie2:DescribeBucketsMetadata
macie2:DescribeClassificationJobMetadata
macie2:DescribeOrganizationConfigurationMetadata
macie2:GetBucketStatisticsMetadata
macie2:GetClassificationExportConfigurationMetadata
macie2:GetCustomDataIdentifierMetadata
macie2:GetFindingStatisticsMetadata
macie2:GetFindingsMetadata
macie2:GetFindingsFilterMetadata
macie2:GetInvitationsCountMetadata
macie2:GetMacieSessionMetadata
macie2:GetMasterAccountMetadata
macie2:GetMemberMetadata
macie2:GetUsageStatisticsMetadata
macie2:GetUsageTotalsMetadata
macie2:ListClassificationJobsMetadata
macie2:ListCustomDataIdentifiersMetadata
macie2:ListFindingsMetadata
macie2:ListFindingsFiltersMetadata
macie2:ListInvitationsMetadata
macie2:ListMembersMetadata
macie2:ListOrganizationAdminAccountsMetadata
macie2:ListTagsForResourceMetadata
macie:DescribeMacieAccountDetailsMetadata
macie:GetIdentityDetailsMetadata
macie:ListMemberAccountsMetadata
macie:ListS3ResourcesMetadata
organizations:DescribeOrganizationMetadata
s3:GetBucketLocationMetadata
s3:ListAllMyBucketsMetadata