Skip to content

aws.verifiedpermissions.get_policy

Example SQL Queries

SELECT * FROM
aws.verifiedpermissions.get_policy
WHERE
"policy_store_id" = 'VALUE'
AND "policy_id" = 'VALUE';

Description

Retrieves information about the specified policy.

Table Definition

Column NameColumn Data Type
policy_id Required Input Column

The unique ID of the policy that you want information about.

VARCHAR
policy_store_id Required Input Column

The ID of the policy store that contains the policy that you want information about.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
actions

The action that a policy permits or forbids. For example, {"actions": [{"actionId": "ViewPhoto", "actionType": "PhotoFlash::Action"}, {"entityID": "SharePhoto", "entityType": "PhotoFlash::Action"}]}.

STRUCT(
"action_type" VARCHAR,
"action_id" VARCHAR
)[]
Show child fields
actions[]
Show child fields
actions[].action_id

The ID of an action.

actions[].action_type

The type of an action.

created_date

The date and time that the policy was originally created.

TIMESTAMP_S
definition

The definition of the requested policy.

STRUCT(
"static" STRUCT(
"description" VARCHAR,
"statement" VARCHAR
),
"template_linked" STRUCT(
"policy_template_id" VARCHAR,
"principal" STRUCT(
"entity_type" VARCHAR,
"entity_id" VARCHAR
),
"resource" STRUCT(
"entity_type" VARCHAR,
"entity_id" VARCHAR
)
)
)
Show child fields
definition.static

Information about a static policy that wasn't created with a policy template.

Show child fields
definition.static.description

A description of the static policy.

definition.static.statement

The content of the static policy written in the Cedar policy language.

definition.template_linked

Information about a template-linked policy that was created by instantiating a policy template.

Show child fields
definition.template_linked.policy_template_id

The unique identifier of the policy template used to create this policy.

definition.template_linked.principal

The principal associated with this template-linked policy. Verified Permissions substitutes this principal for the ?principal placeholder in the policy template when it evaluates an authorization request.

Show child fields
definition.template_linked.principal.entity_id

The identifier of an entity.

"entityId":"identifier"

definition.template_linked.principal.entity_type

The type of an entity.

Example: "entityType":"typeName"

definition.template_linked.resource

The resource associated with this template-linked policy. Verified Permissions substitutes this resource for the ?resource placeholder in the policy template when it evaluates an authorization request.

Show child fields
definition.template_linked.resource.entity_id

The identifier of an entity.

"entityId":"identifier"

definition.template_linked.resource.entity_type

The type of an entity.

Example: "entityType":"typeName"

effect

The effect of the decision that a policy returns to an authorization request. For example, "effect": "Permit".

VARCHAR
last_updated_date

The date and time that the policy was last updated.

TIMESTAMP_S
policy_type

The type of the policy.

VARCHAR
principal

The principal specified in the policy's scope. This element isn't included in the response when Principal isn't present in the policy content.

STRUCT(
"entity_type" VARCHAR,
"entity_id" VARCHAR
)
Show child fields
principal.entity_id

The identifier of an entity.

"entityId":"identifier"

principal.entity_type

The type of an entity.

Example: "entityType":"typeName"

resource

The resource specified in the policy's scope. This element isn't included in the response when Resource isn't present in the policy content.

STRUCT(
"entity_type" VARCHAR,
"entity_id" VARCHAR
)
Show child fields
resource.entity_id

The identifier of an entity.

"entityId":"identifier"

resource.entity_type

The type of an entity.

Example: "entityType":"typeName"