Skip to content

Policy: SageMakerStudioProjectUserRolePolicy

ARN: arn:aws:iam::aws:policy/SageMakerStudioProjectUserRolePolicy

Allowed Actions

Actions Services
airflow:CreateWebLoginToken airflow
airflow:GetEnvironment airflow
airflow:InvokeRestApi airflow
airflow:ListEnvironments airflow
airflow:UpdateEnvironment airflow
athena:BatchGetNamedQuery athena
athena:BatchGetPreparedStatement athena
athena:BatchGetQueryExecution athena
athena:CreateNamedQuery athena
athena:CreateNotebook athena
athena:CreatePreparedStatement athena
athena:CreatePresignedNotebookUrl athena
athena:DeleteNamedQuery athena
athena:DeleteNotebook athena
athena:DeletePreparedStatement athena
athena:ExportNotebook athena
athena:GetCalculationExecution athena
athena:GetCalculationExecutionCode athena
athena:GetCalculationExecutionStatus athena
athena:GetDataCatalog athena
athena:GetDatabase athena
athena:GetNamedQuery athena
athena:GetNotebookMetadata athena
athena:GetPreparedStatement athena
athena:GetQueryExecution athena
athena:GetQueryResults athena
athena:GetQueryResultsStream athena
athena:GetQueryRuntimeStatistics athena
athena:GetSession athena
athena:GetSessionStatus athena
athena:GetTableMetadata athena
athena:GetWorkGroup athena
athena:ImportNotebook athena
athena:ListDataCatalogs athena
athena:ListDatabases athena
athena:ListEngineVersions athena
athena:ListNamedQueries athena
athena:ListPreparedStatements athena
athena:ListQueryExecutions athena
athena:ListTableMetadata athena
athena:ListTagsForResource athena
athena:ListWorkGroups athena
athena:StartCalculationExecution athena
athena:StartQueryExecution athena
athena:StartSession athena
athena:StopCalculationExecution athena
athena:StopQueryExecution athena
athena:TerminateSession athena
athena:UpdateNamedQuery athena
athena:UpdateNotebook athena
athena:UpdateNotebookMetadata athena
athena:UpdatePreparedStatement athena
bedrock:ApplyGuardrail bedrock
bedrock:ApplyGuardrail bedrock
bedrock:BatchDeleteEvaluationJob bedrock
bedrock:BatchDeleteEvaluationJob bedrock
bedrock:CreateAgentAlias bedrock
bedrock:CreateAgentAlias bedrock
bedrock:CreateEvaluationJob bedrock
bedrock:CreateEvaluationJob bedrock
bedrock:CreateEvaluationJob bedrock
bedrock:CreateEvaluationJob bedrock
bedrock:CreatePrompt bedrock
bedrock:CreatePrompt bedrock
bedrock:CreatePromptVersion bedrock
bedrock:CreatePromptVersion bedrock
bedrock:DeleteAgentAlias bedrock
bedrock:DeleteAgentAlias bedrock
bedrock:DeleteAgentVersion bedrock
bedrock:DeleteAgentVersion bedrock
bedrock:DeletePrompt bedrock
bedrock:DeletePrompt bedrock
bedrock:GetAgentAlias bedrock
bedrock:GetAgentAlias bedrock
bedrock:GetAgentVersion bedrock
bedrock:GetAgentVersion bedrock
bedrock:GetEvaluationJob bedrock
bedrock:GetEvaluationJob bedrock
bedrock:GetInferenceProfile bedrock
bedrock:GetInferenceProfile bedrock
bedrock:GetIngestionJob bedrock
bedrock:GetIngestionJob bedrock
bedrock:GetPrompt bedrock
bedrock:GetPrompt bedrock
bedrock:InvokeAgent bedrock
bedrock:InvokeAgent bedrock
bedrock:InvokeFlow bedrock
bedrock:InvokeFlow bedrock
bedrock:InvokeInlineAgent bedrock
bedrock:InvokeInlineAgent bedrock
bedrock:InvokeModel bedrock
bedrock:InvokeModel bedrock
bedrock:InvokeModel bedrock
bedrock:InvokeModel bedrock
bedrock:InvokeModelWithResponseStream bedrock
bedrock:InvokeModelWithResponseStream bedrock
bedrock:InvokeModelWithResponseStream bedrock
bedrock:InvokeModelWithResponseStream bedrock
bedrock:ListAgentAliases bedrock
bedrock:ListAgentAliases bedrock
bedrock:ListAgentVersions bedrock
bedrock:ListAgentVersions bedrock
bedrock:ListEvaluationJobs bedrock
bedrock:ListEvaluationJobs bedrock
bedrock:ListIngestionJobs bedrock
bedrock:ListIngestionJobs bedrock
bedrock:ListPrompts bedrock
bedrock:ListPrompts bedrock
bedrock:ListTagsForResource bedrock
bedrock:ListTagsForResource bedrock
bedrock:Retrieve bedrock
bedrock:Retrieve bedrock
bedrock:RetrieveAndGenerate bedrock
bedrock:RetrieveAndGenerate bedrock
bedrock:StartIngestionJob bedrock
bedrock:StartIngestionJob bedrock
bedrock:StopEvaluationJob bedrock
bedrock:StopEvaluationJob bedrock
bedrock:TagResource bedrock
bedrock:TagResource bedrock
bedrock:UpdateAgentAlias bedrock
bedrock:UpdateAgentAlias bedrock
cloudformation:DescribeStacks cloudformation
cloudformation:DescribeStacks cloudformation
cloudformation:GetTemplate cloudformation
cloudformation:GetTemplate cloudformation
cloudwatch:GetMetricData cloudwatch
cloudwatch:GetMetricStatistics cloudwatch
cloudwatch:PutMetricData cloudwatch
codecommit:BatchDescribeMergeConflicts codecommit
codecommit:BatchGetCommits codecommit
codecommit:BatchGetPullRequests codecommit
codecommit:BatchGetRepositories codecommit
codecommit:CreateBranch codecommit
codecommit:CreateCommit codecommit
codecommit:CreatePullRequest codecommit
codecommit:DeleteBranch codecommit
codecommit:DeleteFile codecommit
codecommit:DescribeMergeConflicts codecommit
codecommit:DescribePullRequestEvents codecommit
codecommit:GetBlob codecommit
codecommit:GetBranch codecommit
codecommit:GetComment codecommit
codecommit:GetCommentReactions codecommit
codecommit:GetCommentsForComparedCommit codecommit
codecommit:GetCommentsForPullRequest codecommit
codecommit:GetCommit codecommit
codecommit:GetCommitHistory codecommit
codecommit:GetCommitsFromMergeBase codecommit
codecommit:GetDifferences codecommit
codecommit:GetFile codecommit
codecommit:GetFolder codecommit
codecommit:GetMergeCommit codecommit
codecommit:GetMergeConflicts codecommit
codecommit:GetMergeOptions codecommit
codecommit:GetObjectIdentifier codecommit
codecommit:GetPullRequest codecommit
codecommit:GetPullRequestApprovalStates codecommit
codecommit:GetPullRequestOverrideState codecommit
codecommit:GetReferences codecommit
codecommit:GetRepository codecommit
codecommit:GetRepositoryTriggers codecommit
codecommit:GetTree codecommit
codecommit:GetUploadArchiveStatus codecommit
codecommit:GitPull codecommit
codecommit:GitPush codecommit
codecommit:ListAssociatedApprovalRuleTemplatesForRepository codecommit
codecommit:ListBranches codecommit
codecommit:ListFileCommitHistory codecommit
codecommit:ListPullRequests codecommit
codecommit:ListTagsForResource codecommit
codecommit:MergeBranchesByFastForward codecommit
codecommit:MergeBranchesBySquash codecommit
codecommit:MergeBranchesByThreeWay codecommit
codecommit:MergePullRequestByFastForward codecommit
codecommit:MergePullRequestBySquash codecommit
codecommit:MergePullRequestByThreeWay codecommit
codecommit:PostCommentForComparedCommit codecommit
codecommit:PostCommentForPullRequest codecommit
codecommit:PostCommentReply codecommit
codecommit:PutCommentReaction codecommit
codecommit:PutFile codecommit
codecommit:UpdateComment codecommit
codecommit:UpdateDefaultBranch codecommit
codecommit:UpdatePullRequestApprovalRuleContent codecommit
codecommit:UpdatePullRequestApprovalState codecommit
codecommit:UpdatePullRequestDescription codecommit
codecommit:UpdatePullRequestStatus codecommit
codecommit:UpdatePullRequestTitle codecommit
codecommit:UpdateRepositoryDescription codecommit
codewhisperer:GenerateRecommendations codewhisperer
datazone:CreateConnection datazone
datazone:DeleteConnection datazone
datazone:GetConnection datazone
datazone:GetDomain datazone
datazone:GetDomainExecutionRoleCredentials datazone
datazone:GetEnvironment datazone
datazone:GetEnvironmentBlueprintConfiguration datazone
datazone:GetProject datazone
datazone:GetUserProfile datazone
datazone:ListConnections datazone
datazone:ListEnvironmentBlueprints datazone
datazone:ListEnvironments datazone
datazone:ListProjects datazone
datazone:PostLineageEvent datazone
datazone:UpdateConnection datazone
dynamodb:ListTables dynamodb
ec2:AttachNetworkInterface ec2
ec2:AttachNetworkInterface ec2
ec2:AuthorizeSecurityGroupEgress ec2
ec2:AuthorizeSecurityGroupIngress ec2
ec2:CreateNetworkInterface ec2
ec2:CreateNetworkInterface ec2
ec2:CreateNetworkInterface ec2
ec2:CreateNetworkInterface ec2
ec2:CreateTags ec2
ec2:DeleteNetworkInterface ec2
ec2:DeleteNetworkInterface ec2
ec2:DeleteTags ec2
ec2:DescribeInstanceTypes ec2
ec2:DescribeNetworkInterfaces ec2
ec2:DescribeNetworkInterfaces ec2
ec2:DescribeRouteTables ec2
ec2:DescribeSecurityGroups ec2
ec2:DescribeSubnets ec2
ec2:DescribeSubnets ec2
ec2:DescribeVpcEndpoints ec2
ec2:DescribeVpcs ec2
ec2:DetachNetworkInterface ec2
ec2:RevokeSecurityGroupEgress ec2
ec2:RevokeSecurityGroupIngress ec2
ecr:BatchCheckLayerAvailability ecr
ecr:BatchDeleteImage ecr
ecr:CompleteLayerUpload ecr
ecr:CreateRepository ecr
ecr:DeleteRepository ecr
ecr:DescribeRepositories ecr
ecr:InitiateLayerUpload ecr
ecr:ListImages ecr
ecr:ListTagsForResource ecr
ecr:PutImage ecr
ecr:TagResource ecr
ecr:UntagResource ecr
ecr:UploadLayerPart ecr
elasticmapreduce:CreatePersistentAppUI elasticmapreduce
elasticmapreduce:DescribeCluster elasticmapreduce
elasticmapreduce:DescribePersistentAppUI elasticmapreduce
elasticmapreduce:GetClusterSessionCredentials elasticmapreduce
elasticmapreduce:GetManagedScalingPolicy elasticmapreduce
elasticmapreduce:GetOnClusterAppUIPresignedURL elasticmapreduce
elasticmapreduce:GetPersistentAppUIPresignedURL elasticmapreduce
elasticmapreduce:ListBootstrapActions elasticmapreduce
elasticmapreduce:ListClusters elasticmapreduce
elasticmapreduce:ListInstanceFleets elasticmapreduce
elasticmapreduce:ListInstanceGroups elasticmapreduce
elasticmapreduce:ListInstances elasticmapreduce
elasticmapreduce:ListReleaseLabels elasticmapreduce
elasticmapreduce:ListSupportedInstanceTypes elasticmapreduce
elasticmapreduce:TerminateJobFlows elasticmapreduce
emr-serverless:AccessInteractiveEndpoints emr-serverless
emr-serverless:AccessLivyEndpoints emr-serverless
emr-serverless:GetApplication emr-serverless
emr-serverless:GetDashboardForJobRun emr-serverless
emr-serverless:GetJobRun emr-serverless
emr-serverless:StartApplication emr-serverless
emr-serverless:StopApplication emr-serverless
glue:BatchCreatePartition glue
glue:BatchDeletePartition glue
glue:BatchDeleteTable glue
glue:BatchDeleteTableVersion glue
glue:BatchGetPartition glue
glue:BatchGetTableOptimizer glue
glue:BatchStopJobRun glue
glue:BatchUpdatePartition glue
glue:CancelDataQualityRuleRecommendationRun glue
glue:CancelDataQualityRulesetEvaluationRun glue
glue:CancelStatement glue
glue:CreateBlueprint glue
glue:CreateDataQualityRuleset glue
glue:CreateDatabase glue
glue:CreateDatabase glue
glue:CreateJob glue
glue:CreatePartition glue
glue:CreatePartitionIndex glue
glue:CreateSession glue
glue:CreateTable glue
glue:CreateWorkflow glue
glue:DeleteBlueprint glue
glue:DeleteColumnStatisticsForPartition glue
glue:DeleteColumnStatisticsForTable glue
glue:DeleteDataQualityRuleset glue
glue:DeleteDatabase glue
glue:DeleteDatabase glue
glue:DeleteJob glue
glue:DeletePartition glue
glue:DeletePartitionIndex glue
glue:DeleteResourcePolicy glue
glue:DeleteSession glue
glue:DeleteTable glue
glue:DeleteTableVersion glue
glue:DeleteWorkflow glue
glue:DescribeConnectionType glue
glue:DescribeEntity glue
glue:GetCatalog glue
glue:GetCatalog glue
glue:GetCatalog glue
glue:GetCatalogImportStatus glue
glue:GetCatalogs glue
glue:GetClassifier glue
glue:GetClassifiers glue
glue:GetColumnStatisticsForPartition glue
glue:GetColumnStatisticsForTable glue
glue:GetColumnStatisticsTaskRun glue
glue:GetColumnStatisticsTaskRuns glue
glue:GetCompletion glue
glue:GetConnection glue
glue:GetConnection glue
glue:GetConnection glue
glue:GetConnections glue
glue:GetConnections glue
glue:GetConnections glue
glue:GetDashboardUrl glue
glue:GetDataQualityModel glue
glue:GetDataQualityModelResult glue
glue:GetDataQualityResult glue
glue:GetDataQualityRuleRecommendationRun glue
glue:GetDataQualityRuleset glue
glue:GetDataQualityRulesetEvaluationRun glue
glue:GetDatabase glue
glue:GetDatabase glue
glue:GetDatabase glue
glue:GetDatabase glue
glue:GetDatabases glue
glue:GetDatabases glue
glue:GetEntityRecords glue
glue:GetGeneratedCode glue
glue:GetPartition glue
glue:GetPartitionIndexes glue
glue:GetPartitions glue
glue:GetSession glue
glue:GetStatement glue
glue:GetTable glue
glue:GetTableOptimizer glue
glue:GetTableVersion glue
glue:GetTableVersions glue
glue:GetTables glue
glue:GetTags glue
glue:GetUserDefinedFunction glue
glue:GetUserDefinedFunction glue
glue:GetUserDefinedFunctions glue
glue:GetUserDefinedFunctions glue
glue:ListConnectionTypes glue
glue:ListCrawls glue
glue:ListDataQualityResults glue
glue:ListDataQualityRuleRecommendationRuns glue
glue:ListDataQualityRulesetEvaluationRuns glue
glue:ListDataQualityRulesets glue
glue:ListEntities glue
glue:ListSessions glue
glue:ListStatements glue
glue:ListTableOptimizerRuns glue
glue:NotifyEvent glue
glue:PassConnection glue
glue:PublishDataQuality glue
glue:PutDataQualityProfileAnnotation glue
glue:PutDataQualityStatisticAnnotation glue
glue:PutResourcePolicy glue
glue:PutWorkflowRunProperties glue
glue:ResumeWorkflowRun glue
glue:RunStatement glue
glue:SearchTables glue
glue:StartBlueprintRun glue
glue:StartCompletion glue
glue:StartDataQualityRuleRecommendationRun glue
glue:StartDataQualityRulesetEvaluationRun glue
glue:StartJobRun glue
glue:StartWorkflowRun glue
glue:StopSession glue
glue:StopWorkflowRun glue
glue:TagResource glue
glue:TagResource glue
glue:UntagResource glue
glue:UpdateBlueprint glue
glue:UpdateCatalog glue
glue:UpdateCatalog glue
glue:UpdateColumnStatisticsForPartition glue
glue:UpdateColumnStatisticsForTable glue
glue:UpdateDataQualityRuleset glue
glue:UpdateJob glue
glue:UpdatePartition glue
glue:UpdateTable glue
glue:UpdateWorkflow glue
glue:UseGlueStudio glue
iam:GetRole iam
iam:ListRoles iam
iam:PassRole iam
iam:PassRole iam
iam:PassRole iam
kms:CreateGrant kms
kms:CreateGrant kms
kms:CreateGrant kms
kms:Decrypt kms
kms:Decrypt kms
kms:Decrypt kms
kms:Decrypt kms
kms:Decrypt kms
kms:Decrypt kms
kms:Decrypt kms
kms:Decrypt kms
kms:Decrypt kms
kms:Decrypt kms
kms:Decrypt kms
kms:DescribeKey kms
kms:DescribeKey kms
kms:DescribeKey kms
kms:Encrypt kms
kms:Encrypt kms
kms:Encrypt kms
kms:Encrypt kms
kms:GenerateDataKey kms
kms:GenerateDataKey kms
kms:GenerateDataKey kms
kms:GenerateDataKey kms
kms:GenerateDataKey kms
kms:GenerateDataKey kms
kms:GenerateDataKey kms
kms:GenerateDataKey kms
kms:GenerateDataKey kms
kms:GenerateDataKey kms
kms:GenerateDataKeyWithoutPlaintext kms
kms:GenerateDataKeyWithoutPlaintext kms
kms:GenerateDataKeyWithoutPlaintext kms
kms:GenerateDataKeyWithoutPlaintext kms
kms:GetPublicKey kms
kms:ListAliases kms
kms:ListGrants kms
kms:ListGrants kms
kms:ReEncryptFrom kms
kms:ReEncryptFrom kms
kms:ReEncryptFrom kms
kms:ReEncryptTo kms
kms:ReEncryptTo kms
kms:ReEncryptTo kms
kms:RevokeGrant kms
lakeformation:BatchGrantPermissions lakeformation
lakeformation:BatchRevokePermissions lakeformation
lakeformation:CreateDataCellsFilter lakeformation
lakeformation:DeleteDataCellsFilter lakeformation
lakeformation:GetDataAccess lakeformation
lakeformation:GetDataCellsFilter lakeformation
lakeformation:ListDataCellsFilter lakeformation
lakeformation:ListPermissions lakeformation
lakeformation:UpdateDataCellsFilter lakeformation
lambda:InvokeFunction lambda
lambda:InvokeFunction lambda
logs:CreateLogGroup logs
logs:CreateLogGroup logs
logs:CreateLogGroup logs
logs:CreateLogStream logs
logs:CreateLogStream logs
logs:CreateLogStream logs
logs:CreateLogStream logs
logs:DescribeLogGroups logs
logs:DescribeLogStreams logs
logs:FilterLogEvents logs
logs:GetLogEvents logs
logs:GetLogEvents logs
logs:GetLogGroupFields logs
logs:GetLogGroupFields logs
logs:GetLogRecord logs
logs:GetLogRecord logs
logs:GetQueryResults logs
logs:GetQueryResults logs
logs:PutLogEvents logs
logs:PutLogEvents logs
logs:PutLogEvents logs
logs:PutLogEvents logs
logs:StartQuery logs
logs:StopQuery logs
pricing:GetProducts pricing
q:SendMessage q
q:StartConversation q
ram:AcceptResourceShareInvitation ram
ram:AssociateResourceShare ram
ram:AssociateResourceSharePermission ram
ram:CreateResourceShare ram
ram:DeleteResourceShare ram
ram:DisassociateResourceShare ram
ram:GetResourceShareInvitations ram
ram:GetResourceShares ram
ram:ListResourceSharePermissions ram
ram:ListResources ram
ram:UpdateResourceShare ram
redshift:DescribeClusters redshift
redshift:DescribeTags redshift
redshift:DescribeTags redshift
redshift:GetClusterCredentialsWithIAM redshift
redshift:GetClusterCredentialsWithIAM redshift
redshift:GetClusterCredentialsWithIAM redshift
redshift-data:BatchExecuteStatement redshift-data
redshift-data:BatchExecuteStatement redshift-data
redshift-data:BatchExecuteStatement redshift-data
redshift-data:CancelStatement redshift-data
redshift-data:CancelStatement redshift-data
redshift-data:DescribeStatement redshift-data
redshift-data:DescribeStatement redshift-data
redshift-data:DescribeTable redshift-data
redshift-data:DescribeTable redshift-data
redshift-data:ExecuteStatement redshift-data
redshift-data:ExecuteStatement redshift-data
redshift-data:ExecuteStatement redshift-data
redshift-data:GetStagingBucketLocation redshift-data
redshift-data:GetStatementResult redshift-data
redshift-data:GetStatementResult redshift-data
redshift-data:ListDatabases redshift-data
redshift-data:ListDatabases redshift-data
redshift-data:ListSchemas redshift-data
redshift-data:ListSchemas redshift-data
redshift-data:ListStatements redshift-data
redshift-data:ListTables redshift-data
redshift-data:ListTables redshift-data
redshift-serverless:GetCredentials redshift-serverless
redshift-serverless:GetCredentials redshift-serverless
redshift-serverless:GetCredentials redshift-serverless
redshift-serverless:GetManagedWorkgroup redshift-serverless
redshift-serverless:GetNamespace redshift-serverless
redshift-serverless:GetNamespace redshift-serverless
redshift-serverless:GetWorkgroup redshift-serverless
redshift-serverless:GetWorkgroup redshift-serverless
redshift-serverless:ListNamespaces redshift-serverless
redshift-serverless:ListTagsForResource redshift-serverless
redshift-serverless:ListTagsForResource redshift-serverless
redshift-serverless:ListWorkgroups redshift-serverless
s3:AbortMultipartUpload s3
s3:DeleteObject s3
s3:DeleteObjectVersion s3
s3:GetAccountPublicAccessBlock s3
s3:GetBucketLocation s3
s3:GetBucketPublicAccessBlock s3
s3:GetEncryptionConfiguration s3
s3:GetObject* s3
s3:GetObject* s3
s3:ListBucket s3
s3:ListBucket s3
s3:ListBucket s3
s3:ListBucket s3
s3:ListBucketVersions s3
s3:ListMultipartUploadParts s3
s3:ListMultipartUploadParts s3
s3:PutObject s3
s3:PutObjectRetention s3
s3:PutObjectTagging s3
s3:ReplicateObject s3
s3:RestoreObject s3
scheduler:CreateSchedule scheduler
scheduler:DeleteSchedule scheduler
scheduler:GetSchedule scheduler
scheduler:GetScheduleGroup scheduler
scheduler:UpdateSchedule scheduler
secretsmanager:DescribeSecret secretsmanager
secretsmanager:DescribeSecret secretsmanager
secretsmanager:DescribeSecret secretsmanager
secretsmanager:GetSecretValue secretsmanager
secretsmanager:GetSecretValue secretsmanager
secretsmanager:GetSecretValue secretsmanager
secretsmanager:ListSecrets secretsmanager
secretsmanager:PutSecretValue secretsmanager
secretsmanager:PutSecretValue secretsmanager
sqlworkbench:CreateConnection sqlworkbench
sqlworkbench:DeleteQCustomContext sqlworkbench
sqlworkbench:DeleteTab sqlworkbench
sqlworkbench:DriverExecute sqlworkbench
sqlworkbench:GetAutocompletionMetadata sqlworkbench
sqlworkbench:GetAutocompletionResource sqlworkbench
sqlworkbench:GetQCustomContext sqlworkbench
sqlworkbench:GetQSqlPromptQuotas sqlworkbench
sqlworkbench:GetQSqlRecommendations sqlworkbench
sqlworkbench:GetQueryExecutionHistory sqlworkbench
sqlworkbench:GetSchemaInference sqlworkbench
sqlworkbench:GetUserInfo sqlworkbench
sqlworkbench:ListQueryExecutionHistory sqlworkbench
sqlworkbench:ListTabs sqlworkbench
sqlworkbench:PassAccountSettings sqlworkbench
sqlworkbench:PutQCustomContext sqlworkbench
sqlworkbench:PutTab sqlworkbench
sqs:ChangeMessageVisibility sqs
sqs:DeleteMessage sqs
sqs:GetQueueAttributes sqs
sqs:GetQueueUrl sqs
sqs:ReceiveMessage sqs
sqs:SendMessage sqs
sts:AssumeRole sts
sts:SetSourceIdentity sts
sts:TagSession sts
tag:GetResources tag