Skip to content

aws.iotsitewise.describe_access_policy

Example SQL Queries

SELECT * FROM
aws.iotsitewise.describe_access_policy
WHERE
"access_policy_id" = 'VALUE';

Description

Describes an access policy, which specifies an identity's access to an IoT SiteWise Monitor portal or project.

Table Definition

Column NameColumn Data Type
access_policy_id Required Input Column

The ID of the access policy.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
access_policy_arn

The ARN of the access policy, which has the following format.

arn:${Partition}:iotsitewise:${Region}:${Account}:access-policy/${AccessPolicyId}

VARCHAR
access_policy_creation_date

The date the access policy was created, in Unix epoch time.

TIMESTAMP_S
access_policy_identity

The identity (IAM Identity Center user, IAM Identity Center group, or IAM user) to which this access policy applies.

STRUCT(
"user" STRUCT(
"id" VARCHAR
),
"group" STRUCT(
"id" VARCHAR
),
"iam_user" STRUCT(
"arn" VARCHAR
),
"iam_role" STRUCT(
"arn" VARCHAR
)
)
Show child fields
access_policy_identity.group

An IAM Identity Center group identity.

Show child fields
access_policy_identity.group.id

The IAM Identity Center ID of the group.

access_policy_identity.iam_role

An IAM role identity.

Show child fields
access_policy_identity.iam_role.arn

The ARN of the IAM role. For more information, see IAM ARNs in the IAM User Guide.

access_policy_identity.iam_user

An IAM user identity.

Show child fields
access_policy_identity.iam_user.arn

The ARN of the IAM user. For more information, see IAM ARNs in the IAM User Guide.

If you delete the IAM user, access policies that contain this identity include an empty arn. You can delete the access policy for the IAM user that no longer exists.

access_policy_identity.user

An IAM Identity Center user identity.

Show child fields
access_policy_identity.user.id

The IAM Identity Center ID of the user.

access_policy_last_update_date

The date the access policy was last updated, in Unix epoch time.

TIMESTAMP_S
access_policy_permission

The access policy permission. Note that a project ADMINISTRATOR is also known as a project owner.

VARCHAR
access_policy_resource

The IoT SiteWise Monitor resource (portal or project) to which this access policy provides access.

STRUCT(
"portal" STRUCT(
"id" VARCHAR
),
"project" STRUCT(
"id" VARCHAR
)
)
Show child fields
access_policy_resource.portal

A portal resource.

Show child fields
access_policy_resource.portal.id

The ID of the portal.

access_policy_resource.project

A project resource.

Show child fields
access_policy_resource.project.id

The ID of the project.