AWS Role Permissions List
Complete reference of IAM permissions and policies required by the WivAccessRole for AWS cost optimization and automation.
Written By Dotan Cohen
Last updated About 1 month ago
Trust Policy (AssumeRolePolicyDocument)
Principal | Condition | Why We Need It |
|
| Allows Wiv's AWS account to assume this role securely; ExternalId prevents confused deputy attacks |
events.amazonaws.com | None | Allows EventBridge service to assume role when executing rules and targets |
apidestinations.events.amazonaws.com | None | Allows EventBridge API Destinations service to assume role for HTTP endpoint invocations |
CloudFormation onboarding parameters
The onboarding stack exposes optional Yes / No flags (default Yes for each) that add or omit whole IAM Allow statements—there is no explicit Deny when you choose No:
Console label | Parameter | When |
Bedrock InvokeModel (BYOC / Wivy) | EnableBedrockInvokeModel | Adds |
Virtual Integration | EnableVirtualIntegration | Adds Billing Views and billing resource-policy APIs on the payer role only: |
WivPayerAccessPolicy
S3 - CUR Bucket Access
Permission | Resource | Why We Need It |
|
| Full access to the CUR bucket itself for managing report storage |
|
| Full access to all CUR report files for reading and processing billing data |
Account & Billing
Permission | Resource | Why We Need It |
| * | Retrieve account-level settings and contact information for account identification |
| * | Access billing dashboard data, preferences, and billing-related settings |
| * | Virtual Integration: list Billing Views for multi-view cost reporting — payer role only; granted when EnableVirtualIntegration is Yes (default). Omitted when No |
| * | Virtual Integration: create Billing Views — payer role only; same conditional as |
| * | Virtual Integration: update Billing Views — payer role only; same conditional |
| * | Virtual Integration: delete Billing Views — payer role only; same conditional |
| * | Virtual Integration: attach resource policies for Billing Views integrations — payer role only; same conditional |
| * | Virtual Integration: remove resource policies — payer role only; same conditional |
| * | Get consolidated billing information across the organization for unified cost views |
| * | List all linked accounts under consolidated billing for multi-account analysis |
| * | List invoices and line items for invoice-level cost tracking |
| * | Get payment methods and payment history for billing health monitoring |
| * | List payment transactions for financial reconciliation |
| * | Get tax settings, exemptions, and tax-related configurations |
| * | List tax registrations and documents for compliance visibility |
Cost Explorer & CUR
Permission | Resource | Why We Need It |
| * | Retrieve cost data, forecasts, reservations, savings plans, and anomaly information |
| * | List cost allocation tags, cost categories, and anomaly monitors |
| * | Describe cost category definitions and report configurations |
| * | Create automated alerts when cost anomalies are detected |
| * | Tag Cost Explorer resources for organization and tracking |
| * | Get Cost and Usage Report definitions and delivery status |
Compute Optimizer
| * | Describe optimization enrollment status and preferences |
| * | Get rightsizing recommendations for EC2, EBS, Lambda, and ECS to reduce costs |
Trusted Advisor
| * | Describe Trusted Advisor check categories and statuses |
| * | Get detailed check results for cost optimization, security, and performance |
| * | List available checks and affected resources |
| * | Refresh checks to get the latest recommendations |
| * | Generate comprehensive Trusted Advisor reports |
| * | Exclude false positives or accepted risks from checks |
| * | Re-include previously excluded items for monitoring |
| * | Describe support cases and service limits |
| * | List all available Trusted Advisor checks |
| * | Get detailed results for specific checks |
| * | Trigger refresh of individual checks for fresh data |
EC2 & Compute
Permission | Effect | Resource | Why We Need It |
| Allow | * | Describe all EC2 resources including instances, volumes, snapshots, reserved instances, and spot pricing for comprehensive compute analysis |
| Deny | * | Explicitly denied to prevent access to sensitive instance attributes (e.g., user data). Overrides the broad |
| Allow | * | List EBS snapshots and volumes for storage cost optimization |
| Allow | * | Describe Auto Scaling groups, policies, and scaling activities for capacity planning |
| Allow | * | Describe Application Auto Scaling targets for ECS, DynamoDB, and other services |
Containers & Kubernetes
| * | Describe ECS clusters, services, tasks, and container instances for container cost analysis |
| * | List ECS resources across all clusters |
| * | Describe ECR repositories and images for storage cost tracking |
| * | List ECR repositories and image tags |
| * | List EKS clusters and node groups for Kubernetes cost visibility |
Serverless
| * | List all Lambda functions for serverless cost tracking |
| * | List provisioned concurrency settings which significantly impact Lambda costs |
| * | List tags on Lambda functions for cost allocation |
Databases
| * | Describe RDS instances, clusters, snapshots, and reserved instances for database cost analysis |
| * | List RDS resources and tags |
| * | Create DB snapshots as part of backup optimization workflows |
| * | Describe DynamoDB tables, capacity modes, and backup settings for NoSQL cost optimization |
| * | List all DynamoDB tables across the account |
| * | List tags on DynamoDB tables for cost allocation |
| * | Describe ElastiCache clusters and reserved nodes for caching cost analysis |
| * | List ElastiCache resources and tags |
| * | Describe Redshift clusters, reserved nodes, and snapshots for data warehouse cost optimization |
Storage
| * | Describe S3 storage lens and configurations |
| * | List all buckets and objects for storage cost analysis |
| * | Check if transfer acceleration is enabled which adds cost |
| * | Check versioning status which impacts storage costs |
| * | Get lifecycle rules to analyze storage optimization opportunities |
| * | List AWS Backup plans, vaults, and jobs for backup cost tracking |
Networking & CDN
| * | Get CloudFront distribution details for CDN cost analysis |
| * | Get distribution configuration to identify optimization opportunities |
| * | List all CloudFront distributions |
| * | Get cache policy settings that affect origin requests and costs |
| * | Describe load balancers, target groups, and listeners for networking cost analysis |
| * | List Route 53 hosted zones for DNS cost tracking |
| * | List hosted zones by domain name for easier identification |
| * | List DNS records to analyze query volumes and costs |
Analytics & Search
| * | Describe OpenSearch/Elasticsearch domains for search service cost analysis |
| * | List OpenSearch domains and tags |
| * | Describe MSK clusters and configurations for streaming cost analysis |
| * | List Kafka clusters and topics |
AI/ML
| * | List SageMaker training jobs for ML cost tracking |
| * | Get training job details including instance types and duration for cost analysis |
| * | List available Bedrock foundation models for discovery and recommendations |
| * | BYOC: invoke Bedrock in the customer account so Wivy can run on customer modules — granted only when EnableBedrockInvokeModel is Yes (default). Omitted when No |
Monitoring & Logging
| * | Describe CloudWatch alarms and dashboards |
| * | Get metrics data for usage analysis and rightsizing recommendations |
| * | List metrics, dashboards, and alarms |
| * | List CloudWatch Log Groups to identify logging costs and optimization opportunities |
| * | Describe CloudTrail trails and their configurations |
| * | Get trail configurations and event selectors |
| * | List trails and tags |
| * | Query CloudTrail events to track resource changes and identify cost-impacting actions |
Config & Compliance
| * | Describe AWS Config rules and configuration recorders |
| * | Get resource configurations and compliance status |
| * | List Config resources, rules, and aggregators |
Other Services
| * | List KMS keys to track encryption-related costs |
| * | List all secrets (just metadata) |
| * | List service quotas for capacity planning and limit monitoring |
| * | List all services with quotas |
| * | Get available Savings Plans offerings to generate purchase recommendations |
Tagging
| * | Get resources by tag for cost allocation and chargeback |
| * | List all tag keys in use across the account |
| * | Get values for specific tag keys for filtering and grouping |
Athena
| {AthenaARN} | Execute SQL queries against CUR data for detailed cost analysis |
| {AthenaARN} | Check query execution status and progress |
| {AthenaARN} | Retrieve query results for reporting and dashboards |
CloudFormation StackSets
| arn:aws:cloudformation:*:{AccountId}:stackset-target/*WivOrgStackSet* | Deploy the Wiv role to member accounts in the organization |
| arn:aws:cloudformation:*:{AccountId}:stackset/*WivOrgStackSet* | Create new stack instances from the StackSet definition |
| arn:aws:cloudformation:*:{AccountId}:stackset-target/*WivOrgStackSet* | Monitor deployment progress to member accounts |
| arn:aws:cloudformation:*:{AccountId}:stackset/*WivOrgStackSet* | Check status of StackSet operations |
| arn:aws:cloudformation:us-east-1::type/resource/AWS-IAM-Role | Permission to provision IAM Role resources in member accounts |
| arn:aws:cloudformation:us-east-1::type/resource/AWS-IAM-Group | Permission to provision IAM Group resources in member accounts |
| arn:aws:cloudformation:us-east-1::type/resource/AWS-IAM-Policy | Permission to provision IAM Policy resources in member accounts |
| arn:aws:cloudformation:us-east-1::type/resource/AWS-CloudFormation-CustomResource | Permission to provision Custom Resources in member accounts |
| arn:aws:cloudformation:us-east-1::type/resource/AWS-S3-Bucket | Permission to provision S3 Bucket resources in member accounts |
| arn:aws:cloudformation:us-east-1::type/resource/AWS-Lambda-Function | Permission to provision Lambda Function resources in member accounts |
Glue
| arn:aws:glue:{Region}:{AccountId}:catalog | Full access to Glue Data Catalog for managing CUR data schema |
| arn:aws:glue:{Region}:{AccountId}:database/wivdb | Manage the wivdb database where CUR tables are stored |
| arn:aws:glue:{Region}:{AccountId}:table/wivdb/* | Manage all tables in wivdb including partitions for Athena queries |
| arn:aws:glue:{Region}:{AccountId}:userDefinedFunction/wivdb/* | Manage user-defined functions for custom data transformations |
OrganizationRetrievalPolicy
| * | Retrieve friendly account alias names to display in Wiv dashboard instead of account IDs |
| * | Get organization ID, master account, and enabled features for org-level context |
| * | Enumerate all member accounts in the organization for multi-account cost visibility |
EventbridgePolicy
EventBridge Rules
Permission | Resource | Condition | Why We Need It |
| * |
| Create EventBridge rules for scheduled cost reports and event-driven workflows |
| * |
| Add targets (API destinations, Lambda) to EventBridge rules |
| * |
| Remove targets from rules during updates or reconfiguration |
| * |
| Delete EventBridge rules during cleanup or disconnection |
| * |
| Apply Wiv tags to EventBridge resources for identification and management |
API Destinations
| * | Create HTTP API endpoints to send events to Wiv's backend for real-time data |
| * | Call the API destination endpoints to deliver event data to Wiv |
| * | Remove API destinations during cleanup or reconfiguration |
| * | View API destination configuration and invocation status |
| * | Create authenticated connections with credentials for secure API calls |
| * | View connection details and authentication status |
Secrets Manager
| arn:aws:secretsmanager:*:{AccountId}:secret:events!connection/* | Create secrets to store EventBridge connection credentials securely |
| arn:aws:secretsmanager:*:{AccountId}:secret:events!connection/* | Store API credential values in secrets |
| arn:aws:secretsmanager:*:{AccountId}:secret:events!connection/* | Update credentials when they rotate or change |
| arn:aws:secretsmanager:*:{AccountId}:secret:events!connection/* | Retrieve credentials for API authentication |
| arn:aws:secretsmanager:*:{AccountId}:secret:events!connection/* | Remove secrets during cleanup |
| arn:aws:secretsmanager:*:{AccountId}:secret:events!connection/* | View secret metadata and rotation configuration |
IAM - Self Role Management
| WivAccessRole ARN | Allow EventBridge and other services to assume this role when invoking targets |
| WivAccessRole ARN | Add inline policies to the role dynamically for EventBridge setup |
| WivAccessRole ARN | List managed policies attached to verify role configuration |
| WivAccessRole ARN | List inline policies to check existing permissions |
| WivAccessRole ARN | Read inline policy documents to verify configuration |
IAM - Service Linked Role
| ...AWSServiceRoleForAmazonEventBridgeApiDestinations | Service: | Create the AWS-managed service-linked role required for API Destinations to function |
| ...AWSServiceRoleForAmazonEventBridgeApiDestinations | None | Attach managed policies to the EventBridge service-linked role |
| ...AWSServiceRoleForAmazonEventBridgeApiDestinations | None | Add inline policies to the EventBridge service-linked role |
Summary by Category
Category | Permission Count | Why We Need It |
S3 (CUR Bucket) | 2 | Read and manage Cost and Usage Report data |
Account & Billing | 9 (+6 optional) | Core billing reads plus invoicing, payments, and tax; six Billing Views / resource-policy APIs on the payer role when Virtual Integration (EnableVirtualIntegration) is Yes |
Cost Explorer & CUR | 6 | Query cost data, forecasts, and anomaly detection |
Compute Optimizer | 2 | Get rightsizing recommendations |
Trusted Advisor | 11 | Access optimization checks and recommendations |
EC2 & Compute | 5 | Analyze compute resources; explicit Deny on sensitive EC2 Describe APIs |
Containers & Kubernetes | 5 | Track ECS, ECR, and EKS costs |
Serverless | 3 | Monitor Lambda functions and provisioned concurrency |
Databases | 9 | Analyze RDS, DynamoDB, ElastiCache, Redshift costs |
Storage | 6 | Track S3, EBS, and backup costs |
Networking & CDN | 8 | Analyze CloudFront, ELB, and Route 53 costs |
Analytics & Search | 4 | Monitor OpenSearch and MSK costs |
AI/ML | 4 | Track SageMaker costs; optional BYOC Bedrock invocation for Wivy on customer modules |
Monitoring & Logging | 8 | Access CloudWatch metrics and CloudTrail events |
Config & Compliance | 3 | Get resource configurations |
Other Services | 3 | Track KMS, quotas, and Savings Plans |
Tagging | 3 | Enable cost allocation by tags |
Athena | 3 | Query CUR data with SQL |
CloudFormation | 10 | Deploy Wiv role to member accounts via StackSets |
Glue | 4 | Manage CUR data catalog for Athena |
Organizations | 3 | List and identify accounts |
EventBridge | 11 | Set up real-time event integration |
Secrets Manager | 6 | Manage API credentials securely |
IAM | 8 | Self-manage role and create service-linked roles |
Total | ~127 (~133 with Virtual Integration on payer) | Complete FinOps visibility and automation |
AWS IAM Permissions Table - WivAccessRole For Payer Account
CrossAccountRole: Type: 'AWS::IAM::Role' Properties: RoleName: WivAccessRole AssumeRolePolicyDocument: Version: 2012-10-17 Statement: - Effect: Allow Principal: AWS: !Sub arn:aws:iam::${WivAccount}:root Action: 'sts:AssumeRole' Condition: StringEquals: 'sts:ExternalId': !Ref ExternalId - Effect: Allow Principal: Service: events.amazonaws.com Action: sts:AssumeRole - Effect: Allow Principal: Service: apidestinations.events.amazonaws.com Action: sts:AssumeRole Tags: - Key: 'Wiv' Value: !Join - '' - - 'Wiv-Infrastructure' - Key: 'Wiv:originalResourceId' Value: 'Payer-Role-Stack' WivPayerAccessPolicy: Type: AWS::IAM::Policy Properties: PolicyName: WivPayerAccessPolicy Roles: - !Ref CrossAccountRole PolicyDocument: Version: 2012-10-17 Statement: - Effect: Allow Action: 's3:*' Resource: - !Join - '' - - 'arn:aws:s3:::' - wiv-cur- - !Ref 'AWS::AccountId' - !Join - '' - - 'arn:aws:s3:::' - wiv-cur- - !Ref 'AWS::AccountId' - /*Note: the original YAML/JSON policy sections continue in the input; preserved formatting and content above per conversion rules.