Skip to content

aws.verifiedpermissions.list_policies

Example SQL Queries

SELECT * FROM
aws.verifiedpermissions.list_policies
WHERE
"policy_store_id" = 'VALUE';

Description

Returns a paginated list of all policies stored in the specified policy store.

Table Definition

Column NameColumn Data Type
policy_store_id Required Input Column

The identifier of the PolicyStore where the policy you want information about is stored.

VARCHAR
filter Input Column

Specifies a filter that limits the response to only policies that match the specified criteria. For example, you list only the policies that reference a specified principal.

STRUCT(
"principal" STRUCT(
"unspecified" BOOLEAN,
"identifier" STRUCT(
"entity_type" VARCHAR,
"entity_id" VARCHAR
)
),
"resource" STRUCT(
"unspecified" BOOLEAN,
"identifier" STRUCT(
"entity_type" VARCHAR,
"entity_id" VARCHAR
)
),
"policy_type" VARCHAR,
"policy_template_id" VARCHAR
)
Show child fields
filter.policy_template_id

Filters the output to only template-linked policies that were instantiated from the specified policy template.

filter.policy_type

Filters the output to only policies of the specified type.

filter.principal

Filters the output to only policies that reference the specified principal.

Show child fields
filter.principal.identifier

The identifier of the entity. It can consist of either an EntityType and EntityId, a principal, or a resource.

Show child fields
filter.principal.identifier.entity_id

The identifier of an entity.

"entityId":"identifier"

filter.principal.identifier.entity_type

The type of an entity.

Example: "entityType":"typeName"

filter.principal.unspecified

Used to indicate that a principal or resource is not specified. This can be used to search for policies that are not associated with a specific principal or resource.

filter.resource

Filters the output to only policies that reference the specified resource.

Show child fields
filter.resource.identifier

The identifier of the entity. It can consist of either an EntityType and EntityId, a principal, or a resource.

Show child fields
filter.resource.identifier.entity_id

The identifier of an entity.

"entityId":"identifier"

filter.resource.identifier.entity_type

The type of an entity.

Example: "entityType":"typeName"

filter.resource.unspecified

Used to indicate that a principal or resource is not specified. This can be used to search for policies that are not associated with a specific principal or resource.

_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
actions

The action that a policy permits or forbids. For example, {"actions": [{"actionId": "ViewPhoto", "actionType": "PhotoFlash::Action"}, {"entityID": "SharePhoto", "entityType": "PhotoFlash::Action"}]}.

STRUCT(
"action_type" VARCHAR,
"action_id" VARCHAR
)[]
Show child fields
actions[]
Show child fields
actions[].action_id

The ID of an action.

actions[].action_type

The type of an action.

created_date

The date and time the policy was created.

TIMESTAMP_S
definition

The policy definition of an item in the list of policies returned.

STRUCT(
"static" STRUCT(
"description" VARCHAR
),
"template_linked" STRUCT(
"policy_template_id" VARCHAR,
"principal" STRUCT(
"entity_type" VARCHAR,
"entity_id" VARCHAR
),
"resource" STRUCT(
"entity_type" VARCHAR,
"entity_id" VARCHAR
)
)
)
Show child fields
definition.static

Information about a static policy that wasn't created with a policy template.

Show child fields
definition.static.description

A description of the static policy.

definition.template_linked

Information about a template-linked policy that was created by instantiating a policy template.

Show child fields
definition.template_linked.policy_template_id

The unique identifier of the policy template used to create this policy.

definition.template_linked.principal

The principal associated with this template-linked policy. Verified Permissions substitutes this principal for the ?principal placeholder in the policy template when it evaluates an authorization request.

Show child fields
definition.template_linked.principal.entity_id

The identifier of an entity.

"entityId":"identifier"

definition.template_linked.principal.entity_type

The type of an entity.

Example: "entityType":"typeName"

definition.template_linked.resource

The resource associated with this template-linked policy. Verified Permissions substitutes this resource for the ?resource placeholder in the policy template when it evaluates an authorization request.

Show child fields
definition.template_linked.resource.entity_id

The identifier of an entity.

"entityId":"identifier"

definition.template_linked.resource.entity_type

The type of an entity.

Example: "entityType":"typeName"

effect

The effect of the decision that a policy returns to an authorization request. For example, "effect": "Permit".

VARCHAR
last_updated_date

The date and time the policy was most recently updated.

TIMESTAMP_S
policy_id

The identifier of the policy you want information about.

VARCHAR
policy_type

The type of the policy. This is one of the following values:

  • static

  • templateLinked

VARCHAR
principal

The principal associated with the policy.

STRUCT(
"entity_type" VARCHAR,
"entity_id" VARCHAR
)
Show child fields
principal.entity_id

The identifier of an entity.

"entityId":"identifier"

principal.entity_type

The type of an entity.

Example: "entityType":"typeName"

resource

The resource associated with the policy.

STRUCT(
"entity_type" VARCHAR,
"entity_id" VARCHAR
)
Show child fields
resource.entity_id

The identifier of an entity.

"entityId":"identifier"

resource.entity_type

The type of an entity.

Example: "entityType":"typeName"