View a markdown version of this page

Actions, resources, and condition keys for AWS Trusted Advisor - Service Authorization Reference

Actions, resources, and condition keys for AWS Trusted Advisor

AWS Trusted Advisor (service prefix: trustedadvisor) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Trusted Advisor

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Actions defined by AWS Trusted Advisor

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

BatchUpdateRecommendationResourceExclusion

Grants permission to update one or more exclusion status for a list of recommendation resources

Write

DeleteNotificationConfigurationForDelegatedAdmin

Grants permission to the organization management account to delete email notification preferences from a delegated administrator account for Trusted Advisor Priority

Write

DescribeCheckItems

Grants permission to view details for the check items

checks*

Read

DescribeCheckRefreshStatuses

Grants permission to view the refresh statuses for AWS Trusted Advisor checks

checks*

Read

DescribeCheckSummaries

Grants permission to view AWS Trusted Advisor check summaries

checks*

Read

DescribeChecks

Grants permission to view details for AWS Trusted Advisor checks

Read

DescribeNotificationConfigurations

Grants permission to get your email notification preferences for Trusted Advisor Priority

Read

DescribeRisk

Grants permission to view risk details in AWS Trusted Advisor Priority

Read

DescribeRiskResources

Grants permission to view affected resources for a risk in AWS Trusted Advisor Priority

Read

DescribeRisks

Grants permission to view risks in AWS Trusted Advisor Priority

Read

DownloadRisk

Grants permission to download a file that contains details about the risk in AWS Trusted Advisor Priority

Read

GetOrganizationRecommendation

Grants permission to get a specific recommendation within an AWS Organization's organization. This API supports only prioritized recommendations

Read

GetRecommendation

Grants permission to get a specific Recommendation

Read

ListChecks

Grants permission to list a filterable set of Checks

List

ListOrganizationRecommendationAccounts

Grants permission to list the accounts that own the resources for an AWS Organization aggregate recommendation. This API only supports prioritized recommendations

List

ListOrganizationRecommendationResources

Grants permission to list Resources of a Recommendation within an AWS Organization. This API only supports prioritized recommendations

List

ListOrganizationRecommendations

Grants permission to list a filterable set of Recommendations within an AWS Organization. This API only supports prioritized recommendations

List

ListRecommendationResources

Grants permission to list Resources of a Recommendation

List

ListRecommendations

Grants permission to list a filterable set of Recommendations

List

ListRecommendationsForResource

Grants permission to list Recommendation of a Resource

List

RefreshCheck

Grants permission to refresh an AWS Trusted Advisor check

checks*

Write

UpdateNotificationConfigurations

Grants permission to create or update your email notification preferences for Trusted Advisor Priority

Write

UpdateOrganizationRecommendationLifecycle

Grants permission to update the lifecyle of a Recommendation within an AWS Organization. This API only supports prioritized recommendations

Write

UpdateRecommendationLifecycle

Grants permission to update the lifecyle of a Recommendation. This API only supports prioritized recommendations

Write

UpdateRiskStatus

Grants permission to update the risk status in AWS Trusted Advisor Priority

Write

Permission-only actions for AWS Trusted Advisor

The following actions are defined by AWS Trusted Advisor but are not directly invocable through any API operation. They can only be used in IAM policy statements to grant or deny permissions.

Actions Description Resource types (*required) Condition keys Access level

DescribeAccount

Grants permission to view the AWS Support plan and various AWS Trusted Advisor preferences

Read

DescribeAccountAccess

Grants permission to view if the AWS account has enabled or disabled AWS Trusted Advisor

Read

DescribeCheckStatusHistoryChanges

Grants permission to view the results and changed statuses for checks in the last 30 days

checks*

Read

DescribeNotificationPreferences

Grants permission to view the notification preferences for the AWS account

Read

DescribeOrganization

Grants permission to view if the AWS account meets the requirements to enable the organizational view feature

Read

DescribeOrganizationAccounts

Grants permission to view the linked AWS accounts that are in the organization

Read

DescribeReports

Grants permission to view details for organizational view reports, such as the report name, runtime, date created, status, and format

Read

DescribeServiceMetadata

Grants permission to view information about organizational view reports, such as the AWS Regions, check categories, check names, and resource statuses