View a markdown version of this page

Actions, resources, and condition keys for AWS Systems Manager Incident Manager Contacts - Service Authorization Reference

Actions, resources, and condition keys for AWS Systems Manager Incident Manager Contacts

AWS Systems Manager Incident Manager Contacts (service prefix: ssm-contacts) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Systems Manager Incident Manager Contacts

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AcceptPage

ssm-contacts:AcceptPage

Write

ActivateContactChannel

ssm-contacts:ActivateContactChannel

Write

CreateContact

ssm-contacts:AssociateContact

Permissions management, Write

ssm-contacts:CreateContact

Write

ssm-contacts:TagResource

Tagging, Write

CreateContactChannel

ssm-contacts:CreateContactChannel

Write

CreateRotation

ssm-contacts:CreateRotation

Write

ssm-contacts:TagResource

Tagging, Write

CreateRotationOverride

ssm-contacts:CreateRotationOverride

Write

DeactivateContactChannel

ssm-contacts:DeactivateContactChannel

Write

DeleteContact

ssm-contacts:DeleteContact

Write

DeleteContactChannel

ssm-contacts:DeleteContactChannel

Write

DeleteRotation

ssm-contacts:DeleteRotation

Write

DeleteRotationOverride

ssm-contacts:DeleteRotationOverride

Write

DescribeEngagement

ssm-contacts:DescribeEngagement

Read

DescribePage

ssm-contacts:DescribePage

Read

GetContact

ssm-contacts:GetContact

Read

GetContactChannel

ssm-contacts:GetContactChannel

Read

GetContactPolicy

ssm-contacts:GetContactPolicy

Read

GetRotation

ssm-contacts:GetRotation

Read

GetRotationOverride

ssm-contacts:GetRotationOverride

Read

ListContactChannels

ssm-contacts:ListContactChannels

List

ListContacts

ssm-contacts:ListContacts

List

ListEngagements

ssm-contacts:ListEngagements

List

ListPageReceipts

ssm-contacts:ListPageReceipts

List

ListPageResolutions

ssm-contacts:ListPageResolutions

List

ListPagesByContact

ssm-contacts:ListPagesByContact

List

ListPagesByEngagement

ssm-contacts:ListPagesByEngagement

List

ListPreviewRotationShifts

ssm-contacts:ListPreviewRotationShifts

List

ListRotationOverrides

ssm-contacts:ListRotationOverrides

List

ListRotationShifts

ssm-contacts:ListRotationShifts

List

ListRotations

ssm-contacts:ListRotations

List

ListTagsForResource

ssm-contacts:ListTagsForResource

Read

PutContactPolicy

ssm-contacts:PutContactPolicy

Write

SendActivationCode

ssm-contacts:SendActivationCode

Write

StartEngagement

ssm-contacts:StartEngagement

Write

StopEngagement

ssm-contacts:StopEngagement

Write

TagResource

ssm-contacts:TagResource

Tagging, Write

UntagResource

ssm-contacts:UntagResource

Tagging, Write

UpdateContact

ssm-contacts:AssociateContact

Permissions management, Write

ssm-contacts:UpdateContact

Write

UpdateContactChannel

ssm-contacts:UpdateContactChannel

Write

UpdateRotation

ssm-contacts:UpdateRotation

Write

Actions defined by AWS Systems Manager Incident Manager Contacts

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AcceptPage

Grants permission to accept a page