Skip to content

aws.iotsitewise.list_access_policies

Example SQL Queries

SELECT * FROM
aws.iotsitewise.list_access_policies;

Description

Retrieves a paginated list of access policies for an identity (an IAM Identity Center user, an IAM Identity Center group, or an IAM user) or an IoT SiteWise Monitor resource (a portal or project).

Table Definition

Column NameColumn Data Type
iam_arn Input Column

The ARN of the IAM user. For more information, see IAM ARNs in the IAM User Guide. This parameter is required if you specify IAM for identityType.

VARCHAR
identity_id Input Column

The ID of the identity. This parameter is required if you specify USER or GROUP for identityType.

VARCHAR
identity_type Input Column

The type of identity (IAM Identity Center user, IAM Identity Center group, or IAM user). This parameter is required if you specify identityId.

VARCHAR
resource_id Input Column

The ID of the resource. This parameter is required if you specify resourceType.

VARCHAR
resource_type Input Column

The type of resource (portal or project). This parameter is required if you specify resourceId.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
creation_date

The date the access policy was created, in Unix epoch time.

TIMESTAMP_S
id

The ID of the access policy.

VARCHAR
identity

The identity (an IAM Identity Center user, an IAM Identity Center group, or an IAM user).

STRUCT(
"user" STRUCT(
"id" VARCHAR
),
"group" STRUCT(
"id" VARCHAR
),
"iam_user" STRUCT(
"arn" VARCHAR
),
"iam_role" STRUCT(
"arn" VARCHAR
)
)
Show child fields
identity.group

An IAM Identity Center group identity.

Show child fields
identity.group.id

The IAM Identity Center ID of the group.

identity.iam_role

An IAM role identity.

Show child fields
identity.iam_role.arn

The ARN of the IAM role. For more information, see IAM ARNs in the IAM User Guide.

identity.iam_user

An IAM user identity.

Show child fields
identity.iam_user.arn

The ARN of the IAM user. For more information, see IAM ARNs in the IAM User Guide.

If you delete the IAM user, access policies that contain this identity include an empty arn. You can delete the access policy for the IAM user that no longer exists.

identity.user

An IAM Identity Center user identity.

Show child fields
identity.user.id

The IAM Identity Center ID of the user.

last_update_date

The date the access policy was last updated, in Unix epoch time.

TIMESTAMP_S
permission

The permissions for the access policy. Note that a project ADMINISTRATOR is also known as a project owner.

VARCHAR
resource

The IoT SiteWise Monitor resource (a portal or project).

STRUCT(
"portal" STRUCT(
"id" VARCHAR
),
"project" STRUCT(
"id" VARCHAR
)
)
Show child fields
resource.portal

A portal resource.

Show child fields
resource.portal.id

The ID of the portal.

resource.project

A project resource.

Show child fields
resource.project.id

The ID of the project.