View a markdown version of this page

Actions, resources, and condition keys for Amazon CloudWatch - Service Authorization Reference

Actions, resources, and condition keys for Amazon CloudWatch

Amazon CloudWatch (service prefix: cloudwatch) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by Amazon CloudWatch

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

DeleteAlarmMuteRule

cloudwatch:DeleteAlarmMuteRule

Write

DeleteAlarms

cloudwatch:DeleteAlarms

Write

DeleteAnomalyDetector

cloudwatch:DeleteAnomalyDetector

Write

DeleteDashboards

cloudwatch:DeleteDashboards

Write

DeleteInsightRules

cloudwatch:DeleteInsightRules

Write

DeleteMetricStream

cloudwatch:DeleteMetricStream

Write

DescribeAlarmHistory

cloudwatch:DescribeAlarmHistory

Read

DescribeAlarms

cloudwatch:DescribeAlarms

Read

DescribeAlarmsForMetric

cloudwatch:DescribeAlarmsForMetric

Read

DescribeAnomalyDetectors

cloudwatch:DescribeAnomalyDetectors

Read

DescribeInsightRules

cloudwatch:DescribeInsightRules

Read

DisableAlarmActions

cloudwatch:DisableAlarmActions

Write

DisableInsightRules

cloudwatch:DisableInsightRules

Write

EnableAlarmActions

cloudwatch:EnableAlarmActions

Write

EnableInsightRules

cloudwatch:EnableInsightRules

Write

GetAlarmMuteRule

cloudwatch:GetAlarmMuteRule

Read

GetDashboard

cloudwatch:GetDashboard

Read

GetDataset

cloudwatch:GetDataset

Read

GetInsightRuleReport

cloudwatch:GetInsightRuleReport

Read

GetMetricData

cloudwatch:GetMetricData

Read

GetMetricStatistics

cloudwatch:GetMetricStatistics

Read

GetMetricStream

cloudwatch:GetMetricStream

Read

GetMetricWidgetImage

cloudwatch:GetMetricWidgetImage

Read

GetOTelEnrichment

cloudwatch:GetOTelEnrichment

Read

ListAlarmMuteRules

cloudwatch:ListAlarmMuteRules

List

ListDashboards

cloudwatch:ListDashboards

List

ListManagedInsightRules

cloudwatch:ListManagedInsightRules

Read

ListMetricStreams

cloudwatch:ListMetricStreams

List

ListMetrics

cloudwatch:ListMetrics

List

ListTagsForResource

cloudwatch:ListTagsForResource

List

oam:ListTagsForResource

Read

PutAlarmMuteRule

cloudwatch:PutAlarmMuteRule

Write

cloudwatch:TagResource

Tagging, Write

PutAnomalyDetector

cloudwatch:PutAnomalyDetector

Write

PutCompositeAlarm

cloudwatch:PutCompositeAlarm

Write

cloudwatch:TagResource

Tagging, Write

PutDashboard

cloudwatch:PutDashboard

Write

cloudwatch:TagResource

Tagging, Write

PutInsightRule

cloudwatch:PutInsightRule

Write

cloudwatch:TagResource

Tagging, Write

PutLogAlarm

cloudwatch:PutLogAlarm

Write

cloudwatch:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

cloudwatch.amazonaws.com

Write

PutManagedInsightRules

cloudwatch:PutManagedInsightRules

Write

PutMetricAlarm

cloudwatch:PutMetricAlarm

Write

cloudwatch:TagResource

Tagging, Write

PutMetricData

cloudwatch:PutMetricData

Write

PutMetricStream

cloudwatch:PutMetricStream

Write

cloudwatch:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

streams.metrics.cloudwatch.amazonaws.com

Write

SetAlarmState

cloudwatch:SetAlarmState

Write

StartMetricStreams

cloudwatch:StartMetricStreams

Write

StartOTelEnrichment

cloudwatch:StartOTelEnrichment

Write

StopMetricStreams

cloudwatch:StopMetricStreams

Write

StopOTelEnrichment

cloudwatch:StopOTelEnrichment

Write

TagResource

cloudwatch:TagResource

Tagging, Write

oam:TagResource

Tagging, Write

UntagResource

cloudwatch:UntagResource

Tagging, Write

oam:UntagResource

Tagging, Write

Actions defined by Amazon CloudWatch

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AssumeAccessProfile

Grants permission to assume an access profile

cloudwatch:HasAccessGrant

Permissions management, Write

BatchGetServiceLevelIndicatorReport

Grants permission to batch get service level indicator report

Read

BatchGetServiceLevelObjectiveBudgetReport

Grants permission to batch retrieve a service level objective budget report

slo*

aws:ResourceTag/${TagKey}

Read

CreateAccessGrant

Grants permission to create an access grant

cloudwatch:HasAccessGrant

Permissions management, Write

CreateAccessProfile

Grants permission to create an access profile

cloudwatch:HasAccessGrant

Permissions management, Write

CreateAlert

Grants permission to create an alert

cloudwatch:HasAccessGrant

Write

CreateDomain

Grants permission to create a domain

Write

CreateDomainAccessGrantForOrganization

Grants permission to create a domain access grant for an organization

cloudwatch:HasAccessGrant

Permissions management, Write

CreateDomainForOrganization

Grants permission to create a domain for an organization

Write

CreateIngestionEndpoint

Grants permission to create an ingestion endpoint

Write

CreateIntegration

Grants permission to create an integration

cloudwatch:HasAccessGrant

Write

CreateOmniDashboard

Grants permission to create an omni dashboard

cloudwatch:HasAccessGrant

Write

CreateOmniThread

Grants permission to create an omni thread

cloudwatch:HasAccessGrant

Write

CreateOneTimeDeepLinkCode

Grants permission to create a one-time deep link code

Write

CreateServiceLevelObjective

Grants permission to create a service level objective

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateSpace

Grants permission to create a space

Write

CreateView

Grants permission to create a view

cloudwatch:HasAccessGrant

Write

DeleteAccessGrant

Grants permission to delete an access grant

access-grant*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Permissions management, Write

DeleteAccessProfile

Grants permission to delete an access profile

access-profile*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Permissions management, Write

DeleteAlarmMuteRule

Grants permission to delete an alarm mute rule

alarm-mute-rule*

aws:ResourceTag/${TagKey}

Write

DeleteAlarms

Grants permission to delete a collection of alarms

alarm*

aws:ResourceTag/${TagKey}

Write

DeleteAlert

Grants permission to delete an alert

alert*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Write

DeleteAnomalyDetector

Grants permission to delete the specified anomaly detection model from your account

Write

DeleteDashboards

Grants permission to delete all CloudWatch dashboards that you specify

dashboard*

aws:ResourceTag/${TagKey}

Write

DeleteDomain

Grants permission to delete a domain

domain*

aws:ResourceTag/${TagKey}

Write

DeleteDomainAccessGrantForOrganization

Grants permission to delete a domain access grant for an organization

organization-access-grant*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Permissions management, Write

DeleteDomainForOrganization

Grants permission to delete a domain for an organization

organization-domain*

aws:ResourceTag/${TagKey}

Write

DeleteIngestionEndpoint

Grants permission to delete an ingestion endpoint

ingestion-endpoint*

aws:ResourceTag/${TagKey}

Write

DeleteInsightRules

Grants permission to delete a collection of insight rules

insight-rule*

aws:ResourceTag/${TagKey}

Write

DeleteIntegration

Grants permission to delete an integration

integration*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Write

DeleteMetricStream

Grants permission to delete the CloudWatch metric stream that you specify

metric-stream*

aws:ResourceTag/${TagKey}

Write

DeleteOmniDashboard

Grants permission to delete an omni dashboard

omni-dashboard*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Write

DeleteOmniThread

Grants permission to delete an omni thread

cloudwatch:HasAccessGrant

Write

DeleteServiceLevelObjective

Grants permission to delete a service level objective

slo*

aws:ResourceTag/${TagKey}

Write

DeleteSpace

Grants permission to delete a space

space*

aws:ResourceTag/${TagKey}

Write

DeleteView

Grants permission to delete a view

view*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Write

DescribeAlarmHistory

Grants permission to retrieve the history for the specified alarm

alarm*

aws:ResourceTag/${TagKey}

Read

DescribeAlarms

Grants permission to describe all alarms, currently owned by the user's account

alarm*

aws:ResourceTag/${TagKey}

Read

DescribeAlarmsForMetric

Grants permission to describe all alarms configured on the specified metric, currently owned by the user's account

Read

DescribeAnomalyDetectors

Grants permission to list the anomaly detection models that you have created in your account

Read

DescribeInsightRules

Grants permission to describe all insight rules, currently owned by the user's account

Read

DisableAlarmActions

Grants permission to disable actions for a collection of alarms

alarm*

aws:ResourceTag/${TagKey}

Write

DisableInsightRules

Grants permission to disable a collection of insight rules

insight-rule*

aws:ResourceTag/${TagKey}

Write

EnableAlarmActions

Grants permission to enable actions for a collection of alarms

alarm*

aws:ResourceTag/${TagKey}

Write

EnableInsightRules

Grants permission to enable a collection of insight rules

insight-rule*

aws:ResourceTag/${TagKey}

Write

EnableTopologyDiscovery

Grants permission to enable a CloudWatch topology discovery

Write

GenerateQuery

Grants permission to generate a Metrics Insights or Logs Insights query string from a natural language prompt

Read

GenerateQueryResultsSummary

Grants permission to generate a summary of CloudWatch LogInsights query results in natural language using generative AI

Read

GetAccessGrant

Grants permission to get an access grant

access-grant*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Read

GetAccessProfile

Grants permission to get an access profile

access-profile*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Read

GetAgentGraph

Grants permission to get an agent graph

Read

GetAlarmMuteRule

Grants permission to get an alarm mute rule

alarm-mute-rule*

aws:ResourceTag/${TagKey}

Read

GetAlert

Grants permission to get an alert

alert*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Read

GetContextGraph

Grants permission to get a context graph

cloudwatch:HasAccessGrant

Read

GetDashboard

Grants permission to display the details of the CloudWatch dashboard you specify

dashboard*

aws:ResourceTag/${TagKey}

Read

GetDataset

Grants permission to get a dataset

dataset*

aws:ResourceTag/${TagKey}

Read

GetDomain

Grants permission to get a domain

domain*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Read

GetDomainAccessGrantForOrganization

Grants permission to get a domain access grant for an organization

organization-access-grant*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Read

GetDomainForOrganization

Grants permission to get a domain for an organization

organization-domain*

aws:ResourceTag/${TagKey}

Read

GetIngestionEndpoint

Grants permission to get an ingestion endpoint

ingestion-endpoint*

aws:ResourceTag/${TagKey}

Read

GetInsightRuleReport

Grants permission to return the top-N report of unique contributors over a time range for a given insight rule

insight-rule*

aws:ResourceTag/${TagKey}

Read

GetIntegration

Grants permission to get an integration

integration*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Read

GetIntelligenceConfiguration

Grants permission to get an intelligence configuration

cloudwatch:HasAccessGrant

Read

GetMetricData

Grants permission to retrieve batch amounts of CloudWatch classic metric data and perform metric math on retrieved data; and grants permission to retrieve OTLP metric data using PromQL

dataset

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Read

GetMetricStatistics

Grants permission to retrieve statistics for the specified metric

Read

GetMetricStream

Grants permission to return the details of a CloudWatch metric stream

metric-stream*

aws:ResourceTag/${TagKey}

Read

GetMetricWidgetImage

Grants permission to retrieve snapshots of metric widgets

Read

GetOmniDashboard

Grants permission to get an omni dashboard

omni-dashboard*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Read

GetOmniThread

Grants permission to get an omni thread

cloudwatch:HasAccessGrant

Read

GetPreferences

Grants permission to get preferences

cloudwatch:HasAccessGrant

Read

GetRecords

Grants permission to fetch logs, metrics, and traces

cloudwatch:HasAccessGrant

Read

GetService

Grants permission to retrieve information about a service

service*

aws:ResourceTag/${TagKey}

Read

GetServiceLevelObjective

Grants permission to retrieve information about service level objective

slo*

aws:ResourceTag/${TagKey}

Read

GetSpace

Grants permission to get a space

space*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Read

GetSpaceCredentials

Grants permission to get space credentials

Read

GetSpaceCredentialsForOrganization

Grants permission to get space credentials for an organization

Read

GetTelemetryQueryResults

Grants permission to get telemetry query results

cloudwatch:HasAccessGrant

Read

GetTopologyMap

Grants permission to retrieve a CloudWatch topology map

Read

GetView

Grants permission to get a view

view*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Read

InvokeIntegration

Grants permission to invoke an integration

cloudwatch:HasAccessGrant

Write

ListAccessGrants

Grants permission to list access grants

cloudwatch:HasAccessGrant

List

ListAccessProfiles

Grants permission to list access profiles

cloudwatch:HasAccessGrant

List

ListAlarmMuteRules

Grants permission to retrieve a list of alarm mute rules owned by the user's account

alarm-mute-rule*

aws:ResourceTag/${TagKey}

List

ListAlertContributors

Grants permission to list alert contributors

cloudwatch:HasAccessGrant

List

ListAlerts

Grants permission to list alerts

cloudwatch:HasAccessGrant

List

ListDashboards

Grants permission to return a list of all CloudWatch dashboards in your account

List

ListDomainAccessGrantsForOrganization

Grants permission to list domain access grants for an organization

cloudwatch:HasAccessGrant

List

ListDomains

Grants permission to list domains

List

ListIngestionEndpoints

Grants permission to list ingestion endpoints

List

ListIntegrations

Grants permission to list integrations

cloudwatch:HasAccessGrant

List

ListManagedInsightRules

Grants permission to list available managed Insight Rules for a given Resource ARN

aws:RequestTag/${TagKey}

aws:TagKeys

cloudwatch:requestManagedResourceARNs

Read

ListMetricStreams

Grants permission to return a list of all CloudWatch metric streams in your account

List

ListMetrics

Grants permission to retrieve a list of valid metrics stored for the AWS account owner

dataset

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

List

ListOmniDashboards

Grants permission to list omni dashboards

cloudwatch:HasAccessGrant

List

ListOmniThreads

Grants permission to list omni threads

cloudwatch:HasAccessGrant

List

ListServiceLevelObjectives

Grants permission to list service level objectives

List

ListServices

Grants permission to list services

List

ListSpaceAccess

Grants permission to list access to a space

cloudwatch:HasAccessGrant

List

ListSpaces

Grants permission to list spaces

cloudwatch:HasAccessGrant

List

ListSpacesForOrganization

Grants permission to list spaces for an organization

cloudwatch:HasAccessGrant

List

ListTagsForResource

Grants permission to list tags for an Amazon CloudWatch resource

alarm

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

List

alarm-mute-rule

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

dashboard

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

dataset

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

insight-rule

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

metric-stream

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

service

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

slo

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

SCENARIO: CloudWatch-Alarm

alarm*

SCENARIO: CloudWatch-AlarmMuteRule

alarm-mute-rule*

SCENARIO: CloudWatch-InsightRule

insight-rule*

SCENARIO: CloudWatch-ServiceLevelObjective

slo*

SCENARIO: CloudWatch-Dashboard

dashboard*

SCENARIO: CloudWatch-Dataset

dataset*

SCENARIO: CloudWatch-MetricStream

metric-stream*

SCENARIO: CloudWatch-Service

service*

ListTelemetryFields

Grants permission to list telemetry fields

cloudwatch:HasAccessGrant

List

ListTelemetryQuerySessions

Grants permission to list telemetry query sessions

cloudwatch:HasAccessGrant

List

ListViews

Grants permission to list views

cloudwatch:HasAccessGrant

List

PutAlarmMuteRule

Grants permission to create or update an alarm mute rule

alarm

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

alarm-mute-rule*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

PutAnomalyDetector

Grants permission to create or update an anomaly detection model for a CloudWatch metric

Write

PutCompositeAlarm

Grants permission to create or update a composite alarm

alarm*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:AlarmActions

Write

PutDashboard

Grants permission to create a CloudWatch dashboard, or update an existing dashboard if it already exists

dashboard*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

PutInsightRule

Grants permission to create a new insight rule or replace an existing insight rule

insight-rule*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:requestInsightRuleLogGroups

Write

PutIntelligenceConfiguration

Grants permission to configure an intelligence configuration

cloudwatch:HasAccessGrant

Write

PutLogAlarm

Grants permission to create or update a log-based alarm and associate it with a CloudWatch Logs Insights scheduled query

alarm*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:AlarmActions

Write

PutManagedInsightRules

Grants permission to create managed Insight Rules

aws:RequestTag/${TagKey}

aws:TagKeys

cloudwatch:requestManagedResourceARNs

Write

PutMetricAlarm

Grants permission to create or update an alarm and associates it with the specified Amazon CloudWatch metric

alarm*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:AlarmActions

Write

dataset

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:AlarmActions

PutMetricData

Grants permission to publish metric data points to Amazon CloudWatch using CloudWatch and OTLP formats

dataset

aws:ResourceTag/${TagKey}

cloudwatch:namespace

Write

PutMetricStream

Grants permission to create a CloudWatch metric stream, or update an existing metric stream if it already exists

metric-stream*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

QueryTraces

Grants permission to query traces

Write

SearchPrincipals

Grants permission to search principals

cloudwatch:HasAccessGrant

Write

SetAlarmState

Grants permission to temporarily set the state of an alarm for testing purposes

alarm*

aws:ResourceTag/${TagKey}

Write

StartMetricStreams

Grants permission to start all CloudWatch metric streams that you specify

metric-stream*

aws:ResourceTag/${TagKey}

Write

StartOmniThreadSession

Grants permission to start an omni thread session

cloudwatch:HasAccessGrant

Write

StartTelemetryQuery

Grants permission to start a telemetry query

cloudwatch:HasAccessGrant

Write

StartTelemetryQuerySession

Grants permission to start a telemetry query session

cloudwatch:HasAccessGrant

Write

StopMetricStreams

Grants permission to stop all CloudWatch metric streams that you specify

metric-stream*

aws:ResourceTag/${TagKey}

Write

StopTelemetryQuery

Grants permission to stop a telemetry query

cloudwatch:HasAccessGrant

Write

StopTelemetryQuerySession

Grants permission to stop a telemetry query session

cloudwatch:HasAccessGrant

Write

SubmitFeedback

Grants permission to submit feedback

cloudwatch:HasAccessGrant

Write

TagResource

Grants permission to add tags to an Amazon CloudWatch resource

alarm

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

Tagging, Write

alarm-mute-rule

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

dashboard

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

dataset

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

insight-rule

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

metric-stream

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

service

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

slo

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

SCENARIO: CloudWatch-Alarm

alarm*

SCENARIO: CloudWatch-AlarmMuteRule

alarm-mute-rule*

SCENARIO: CloudWatch-InsightRule

insight-rule*

SCENARIO: CloudWatch-ServiceLevelObjective

slo*

SCENARIO: CloudWatch-Dashboard

dashboard*

SCENARIO: CloudWatch-Dataset

dataset*

SCENARIO: CloudWatch-MetricStream

metric-stream*

SCENARIO: CloudWatch-Service

service*

UntagResource

Grants permission to remove a tag from an Amazon CloudWatch resource

alarm

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

Tagging, Write

alarm-mute-rule

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

dashboard

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

dataset

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

insight-rule

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

metric-stream

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

service

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

slo

aws:ResourceTag/${TagKey}

aws:TagKeys

cloudwatch:HasAccessGrant

SCENARIO: CloudWatch-Alarm

alarm*

SCENARIO: CloudWatch-AlarmMuteRule

alarm-mute-rule*

SCENARIO: CloudWatch-InsightRule

insight-rule*

SCENARIO: CloudWatch-ServiceLevelObjective

slo*

SCENARIO: CloudWatch-Dashboard

dashboard*

SCENARIO: CloudWatch-Dataset

dataset*

SCENARIO: CloudWatch-MetricStream

metric-stream*

SCENARIO: CloudWatch-Service

service*

UpdateAccessProfile

Grants permission to update an access profile

access-profile*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Permissions management, Write

UpdateAlert

Grants permission to update an alert

alert*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Write

UpdateDomain

Grants permission to update a domain

domain*

aws:ResourceTag/${TagKey}

Write

UpdateDomainForOrganization

Grants permission to update a domain for an organization

organization-domain*

aws:ResourceTag/${TagKey}

Write

UpdateIngestionEndpoint

Grants permission to update an ingestion endpoint

ingestion-endpoint*

aws:ResourceTag/${TagKey}

Write

UpdateIntegration

Grants permission to update an integration

integration*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Write

UpdateOmniDashboard

Grants permission to update an omni dashboard

omni-dashboard*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Write

UpdateOmniThread

Grants permission to update an omni thread

cloudwatch:HasAccessGrant

Write

UpdatePreferences

Grants permission to update preferences

cloudwatch:HasAccessGrant

Write

UpdateServiceLevelObjective

Grants permission to update a service level objective

slo*

aws:ResourceTag/${TagKey}

Write

UpdateSpace

Grants permission to update a space

space*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Write

UpdateView

Grants permission to update a view

view*

aws:ResourceTag/${TagKey}

cloudwatch:HasAccessGrant

Write

Permission-only actions for Amazon CloudWatch

The following actions are defined by Amazon CloudWatch but are not directly invocable through any API operation. They can only be used in IAM policy statements to grant or deny permissions.

Actions Description Resource types (*required) Condition keys Access level

CallWithBearerToken

Grants permission to make API calls to CloudWatch using bearer token authentication

Write

DeletePipelineRule

Grants permission to delete a pipeline rule for CloudWatch pipelines for OTel metric processing

dataset*

aws:ResourceTag/${TagKey}

Write

GetOTelEnrichment

Grants permission to retrieve the status of OTel Enrichment of vended metrics for PromQL querying

Read

GetServiceData

Grants permission to retrieve service data

service*

aws:ResourceTag/${TagKey}

Read

GetTopologyDiscoveryStatus

Grants permission to retrieve a CloudWatch topology discovery status

Read

Link

Grants permission to share CloudWatch resources with a monitoring account

Write

ListEntitiesForMetric

Grants permission to retrieve all the entities that are emitting a given metric

List

PutPipelineRule

Grants permission to create or update a pipeline rule for CloudWatch pipelines for OTel metric processing

dataset*

aws:ResourceTag/${TagKey}

Write

StartOTelEnrichment

Grants permission to enable OTel Enrichment of vended metrics for PromQL querying

Write

StopOTelEnrichment

Grants permission to disable OTel Enrichment of vended metrics for PromQL querying

Write

Resource types defined by Amazon CloudWatch

The following resource types are defined by this service and can be used in the Resource element of IAM permission policy statements.

Resource types ARN Condition keys

access-grant

arn:${Partition}:cloudwatch:${Region}:${Account}:access-grant/${GrantId}

aws:ResourceTag/${TagKey}

access-profile

arn:${Partition}:cloudwatch:${Region}:${Account}:access-profile/${ProfileId}

aws:ResourceTag/${TagKey}

alarm

arn:${Partition}:cloudwatch:${Region}:${Account}:alarm:${AlarmName}

aws:ResourceTag/${TagKey}

alarm-mute-rule

arn:${Partition}:cloudwatch:${Region}:${Account}:alarm-mute-rule:${AlarmMuteRuleName}

aws:ResourceTag/${TagKey}

alert

arn:${Partition}:cloudwatch:${Region}:${Account}:alert/${AlertId}

aws:ResourceTag/${TagKey}

dashboard

arn:${Partition}:cloudwatch::${Account}:dashboard/${DashboardName}

aws:ResourceTag/${TagKey}

dataset

arn:${Partition}:cloudwatch:${Region}:${Account}:dataset/${DatasetId}

aws:ResourceTag/${TagKey}

domain

arn:${Partition}:cloudwatch:${Region}:${Account}:domain/${DomainId}

aws:ResourceTag/${TagKey}

ingestion-endpoint

arn:${Partition}:cloudwatch:${Region}:${Account}:ingestion-endpoint/${IngestionEndpointName}/${IngestionEndpointId}

aws:ResourceTag/${TagKey}

insight-rule

arn:${Partition}:cloudwatch:${Region}:${Account}:insight-rule/${InsightRuleName}

aws:ResourceTag/${TagKey}

integration

arn:${Partition}:cloudwatch:${Region}:${Account}:integration/${IntegrationId}

aws:ResourceTag/${TagKey}

metric-stream

arn:${Partition}:cloudwatch:${Region}:${Account}:metric-stream/${MetricStreamName}

aws:ResourceTag/${TagKey}

omni-dashboard

arn:${Partition}:cloudwatch:${Region}:${Account}:omni-dashboard/${DashboardId}

aws:ResourceTag/${TagKey}

organization-access-grant

arn:${Partition}:cloudwatch:${Region}:${Account}:organization-access-grant/${GrantId}

aws:ResourceTag/${TagKey}

organization-domain

arn:${Partition}:cloudwatch:${Region}:${Account}:organization-domain/${DomainId}

aws:ResourceTag/${TagKey}

service

arn:${Partition}:cloudwatch:${Region}:${Account}:service/${ServiceName}-${UniqueAttributesHex}

aws:ResourceTag/${TagKey}

slo

arn:${Partition}:cloudwatch:${Region}:${Account}:slo/${SloName}

aws:ResourceTag/${TagKey}

space

arn:${Partition}:cloudwatch:${Region}:${Account}:space/${SpaceId}

aws:ResourceTag/${TagKey}

view

arn:${Partition}:cloudwatch:${Region}:${Account}:view/${ViewName}

aws:ResourceTag/${TagKey}

Condition keys for Amazon CloudWatch

Amazon CloudWatch defines the following condition keys that can be used in the Condition element of an IAM policy.

Condition keys Description Type

aws:RequestTag/${TagKey}

Filters access by the presence of tags in the request

String

aws:ResourceTag/${TagKey}

Filters access by tags associated with the resource

String

aws:TagKeys

Filters access by the presence of tags in the request

ArrayOfString

cloudwatch:AlarmActions

Filters access by defined alarm actions

ArrayOfString

cloudwatch:HasAccessGrant

Filters access by the presence of access grants associated with the request

String

cloudwatch:namespace

Filters access by the presence of optional namespace values

String

cloudwatch:requestInsightRuleLogGroups

Filters access by the Log Groups specified in an Insight Rule

ArrayOfString

cloudwatch:requestManagedResourceARNs

Filters access by the Resource ARNs specified in a managed Insight Rule

ArrayOfARN