Permissions
This page lists all the permissions in the managed policy DoiTMspEvidenceReadOnly-v1 that is used to collect AWS evidence for MSP assessment, when connecting AWS accounts to the MSP Workspace.
Backup depth
| Permission | Description |
|---|---|
backup:ListBackupPlans | Lists the active backup plans for the account. |
backup:ListBackupVaults | Returns a list of recovery point storage containers along with information about them. |
backup:ListBackupJobs | Returns a list of existing backup jobs for an authenticated account for the last 30 days. |
backup:ListRestoreJobs | Returns a list of jobs that AWS Backup initiated to restore a saved resource, including details about the recovery process. |
Support plan probe
| Permission | Description |
|---|---|
support:DescribeSeverityLevels | Returns the list of severity levels that you can assign to a support case. |
support:DescribeTrustedAdvisorChecks | Returns information about all available AWS Trusted Advisor checks, including the name, ID, category, description, and metadata. |
support:DescribeTrustedAdvisorCheckResult | Returns the results of the AWS Trusted Advisor check that has the specified check ID. |
support:DescribeTrustedAdvisorCheckSummaries | Returns the results for the AWS Trusted Advisor check summaries for the check IDs that you specified. |
Well-Architected Tool
| Permission | Description |
|---|---|
wellarchitected:ListWorkloads | Returns a paginated list of workloads. |
wellarchitected:GetWorkload | Retrieves an existing workload. |
wellarchitected:ListAnswers | Lists answers for a particular workload and lens. |
Cost visibility
| Permission | Description |
|---|---|
ce:GetCostAndUsage | Retrieves cost and usage metrics for your account. |
ce:GetRightsizingRecommendation | Creates recommendations that help you save cost by identifying idle and underutilized Amazon EC2 instances. |
ce:GetSavingsPlansPurchaseRecommendation | Retrieves the Savings Plans recommendations for your account. |
DevOps Guru
| Permission | Description |
|---|---|
devops-guru:DescribeServiceIntegration | Returns the integration status of services that are integrated with DevOps Guru. |
devops-guru:ListInsights | Returns a list of insights in your AWS account. |
Pipeline history
| Permission | Description |
|---|---|
codepipeline:GetPipeline | Returns the metadata, structure, stages, and actions of a pipeline. |
codepipeline:GetPipelineExecution | Returns information about an execution of a pipeline, including details about artifacts, the pipeline execution ID, and the name, version, and status of the pipeline. |
codepipeline:ListPipelines | Gets a summary of all of the pipelines associated with your account. |
codepipeline:ListPipelineExecutions | Gets a summary of the most recent executions for a pipeline. |
codebuild:ListProjects | Gets a list of build project names, with each build project name representing a single build project. |
codebuild:BatchGetProjects | Gets information about one or more build projects. |
codebuild:ListBuilds | Gets a list of build IDs, with each build ID representing a single build. |
codebuild:ListBuildsForProject | Gets a list of build identifiers for the specified build project, with each build identifier representing a single build. |
codebuild:BatchGetBuilds | Gets information about one or more builds. |