---
title: How to configure Hyperglance's AWS IAM requirements
description: Get the most from Hyperglance by connecting it to AWS
---

[Skip to content](https://support.hyperglance.com/knowledge/aws-iam-policy-requirements#main-content)

English

Show submenu for translations

[More support](https://support.hyperglance.com/knowledge/kb-tickets/new?hsLang=en)

![](https://support.hyperglance.com/hs-fs/hubfs/hyperglance.png?width=100&height=75&name=hyperglance.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [More support](https://support.hyperglance.com/knowledge/kb-tickets/new)
- [Contact Us](https://www.hyperglance.com/contact/)

[Contact Us](https://www.hyperglance.com/contact/)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Hyperglance Support](https://support.hyperglance.com/knowledge?hsLang=en)
2. [Setup & Configuration](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en)
3. [AWS](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#aws)

# How to configure Hyperglance's AWS IAM requirements

## Get the most from Hyperglance by connecting it to AWS

Hyperglance IAM Permissions

If you're connecting Hyperglance to an [AWS GovCloud](https://www.hyperglance.com/platforms/aws/aws-govcloud/) account, follow [these instructions instead](https://support.hyperglance.com/knowledge/aws-iam-policy-requirements-for-govcloud?hsLang=en).

The [Hyperglance](https://www.hyperglance.com/) IAM user needs certain rights to poll the relevant information from the API to [gather inventory, create diagrams](https://www.hyperglance.com/features/automatic-cloud-diagram/), and [evaluate cost-saving, compliance, and security rules](https://www.hyperglance.com/features/cloud-automation/).

Choose between our general read policy or our high-specific one that grants minimum-required permissions:

- [General Read-Only Policy](https://support.hyperglance.com/knowledge/aws-iam-policy-requirements#generic-read-only)
- [Specific Read-Only Policy](https://support.hyperglance.com/knowledge/aws-iam-policy-requirements#detailed-read-only)<https://support.hyperglance.com/knowledge/aws-iam-policy-requirements#detailed-read-write>
- [Sending SNS Notifications](https://support.hyperglance.com/knowledge/aws-iam-policy-requirements#sns)

#### **General Read-Only Policy**

The general policy broadly wildcards lots of the read and list permissions. This is easier to maintain and means less maintenance of the policy for you as we add more features to Hyperglance. If you would rather be more specific on the permissions then see or specific policy further down.

```
{    "Version": "2012-10-17",    "Statement": [        {            "Effect": "Allow",            "Action": [                "access-analyzer:List*",                "apigateway:GET",                "autoscaling:Describe*",                "backup:ListProtectedResources",                "cloudwatch:Describe*",                "cloudwatch:GetMetricStatistics",                "cloudwatch:ListMetrics",                "cur:DescribeReportDefinitions",                "dax:Describe*",                "dax:ListTags",                "dynamodb:Describe*",                "dynamodb:ListTables",                "dynamodb:ListTagsOfResource",                "directconnect:Describe*",                "ec2:Describe*",                "ec2:Get*",                "ec2:Search*",                "ecs:Describe*",                "ecs:List*",                "eks:Describe*",                "eks:List*",                "elasticloadbalancing:Describe*",                "iam:List*",                "iam:Get*",                "iam:GenerateCredentialReport",                "lambda:List*",                "ram:GetResourceShareAssociations",                "redshift:Describe*",                "redshift:List*",                "rds:Describe*",                "rds:ListTagsForResource",                "route53:List*",                "route53:Get*",                "s3:Get*",                "s3:ListAllMyBuckets",                "s3:ListBucket",                "sts:AssumeRole",                "sts:GetCallerIdentity",                "workspaces:Describe*",                "sns:List*",                "sns:Get*",                "sqs:List*",                "sqs:Get*",                "pricing:GetProducts"            ],            "Resource": "*"        }    ]}
```

#### **Specific Read-Only Policy**

The specific policy grants only the exact permissions that Hyperglance needs. However as we add more coverage to Hyperglance you will have to amend the policy more frequently.

```
{	"Version": "2012-10-17",	"Statement": [		{			"Effect": "Allow",			"Action": [                                "access-analyzer:ListAnalyzers",                                "apigateway:GET",				"autoscaling:Describe*",                                "backup:ListProtectedResources",				"cloudwatch:Describe*",				"cloudwatch:GetMetricStatistics",				"cloudwatch:ListMetrics",                                "cur:DescribeReportDefinitions",				"dax:Describe*",				"dax:ListTags",				"dynamodb:Describe*",				"dynamodb:ListTables",				"dynamodb:ListTagsOfResource",                                "directconnect:DescribeLags",                                "directconnect:DescribeConnections",                                "directconnect:DescribeVirtualInterfaces",                                "directconnect:DescribeDirectConnectGateways",                                "directconnect:DescribeDirectConnectGatewayAssociations",				"ec2:Describe*",                                "ec2:GetEbsEncryptionByDefault",				"ec2:GetTransitGatewayRouteTablePropagations",                                "ec2:SearchTransitGatewayRoutes",				"ecs:describeClusters",				"ecs:describeContainerInstances",				"ecs:describeServices",				"ecs:describeTasks",				"ecs:listClusters",				"ecs:listContainerInstances",				"ecs:listServices",				"ecs:listTasks",                                "eks:DescribeCluster",                                "eks:DescribeFargateProfile",                                "eks:DescribeUpdate",                                "eks:DescribeNodegroup",                                "eks:ListClusters",                                "eks:ListUpdates",                                "eks:ListFargateProfiles",                                "eks:ListNodegroups",                                "eks:ListTagsForResource",		        	"elasticloadbalancing:Describe*",				"elasticloadbalancing:DescribeAccountLimits",				"elasticloadbalancing:DescribeInstanceHealth",				"elasticloadbalancing:DescribeListenerCertificates",				"elasticloadbalancing:DescribeListeners",				"elasticloadbalancing:DescribeLoadBalancerAttributes",				"elasticloadbalancing:DescribeLoadBalancers",				"elasticloadbalancing:DescribeRules",				"elasticloadbalancing:DescribeSSLPolicies",				"elasticloadbalancing:DescribeTags",				"elasticloadbalancing:DescribeTargetGroupAttributes",				"elasticloadbalancing:DescribeTargetGroups",				"elasticloadbalancing:DescribeTargetHealth",                                "iam:ListAttachedUserPolicies",                                "iam:ListEntitiesForPolicy",                                                                "iam:ListPolicies",                                "iam:ListUserPolicies",                                "iam:ListUsers",                                "iam:ListMFADevices",                                "iam:ListServerCertificates",                                "iam:ListGroupsForUser",                                "iam:ListSSHPublicKeys",                                "iam:ListAccessKeys",                                "iam:GetAccessKeyLastUsed",                                "iam:GetAccountPasswordPolicy",                                "iam:GetCredentialReport",                                "iam:GetPolicyVersion",                                "iam:GenerateCredentialReport",				"lambda:List*",				"ram:GetResourceShareAssociations",				"redshift:describeClusterSubnetGroups",				"redshift:describeClusters",				"redshift:describeTags",				"rds:Describe*",				"rds:ListTagsForResource",                                "route53:ListTrafficPolicyInstances",                                "route53:ListTrafficPolicyVersions",                                "route53:ListResourceRecordSets",                                "route53:ListHostedZones",                                "route53:GetHostedZone",				"s3:GetAccelerateConfiguration",				"s3:GetAnalyticsConfiguration",				"s3:GetBucketAcl",				"s3:GetBucketCORS",				"s3:GetBucketLocation",				"s3:GetBucketLogging",				"s3:GetBucketNotification",				"s3:GetBucketPolicy",				"s3:GetBucketRequestPayment",				"s3:GetBucketTagging",				"s3:GetBucketVersioning",				"s3:GetBucketWebsite",				"s3:GetEncryptionConfiguration",				"s3:GetInventoryConfiguration",				"s3:GetLifecycleConfiguration",				"s3:GetMetricsConfiguration",				"s3:GetBucketPublicAccessBlock",				"s3:GetReplicationConfiguration",                                "s3:GetObject",				"s3:ListAllMyBuckets",                                "s3:ListBucket",				"sts:AssumeRole",				"sts:GetCallerIdentity",                                "workspaces:DescribeWorkspaces",                                "workspaces:DescribeWorkspaceDirectories",                                "workspaces:DescribeWorkspaceBundles",                                "workspaces:DescribeWorkspacesConnectionStatus",                                "sns:ListTopics",                                "sns:ListSubscriptions",                                "sns:ListTagsForResource",                                "sns:GetTopicAttributes",                                "sqs:ListQueues",                                "sqs:GetQueueAttributes",                                 "sqs:ListQueueTags",                                "pricing:GetProducts"			],			"Resource": "*"		}	]}
```

#### Sending SNS Notifications

In order to send SNS notifications using Hyperglance's rules, you'll need to add an SNS Publish permission to the policy:

```
"sns:Publish",
```

---

 

- [Before You Start](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#main-content)

    - [Kubernetes](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#kubernetes)
    - [GCP](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#gcp)
    - [AWS](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#aws)
    - [Azure](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#azure)
- [Using Hyperglance](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#main-content)

    - [Automations](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#automations)
    - [Inventory & Diagrams](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#inventory-diagrams)
    - [Rules](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#rules)
    - [Cost Management](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#cost-management)
    - [Dashboards](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#dashboards)
    - [Security & Compliance](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#security-compliance)
- [Setup & Configuration](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#main-content)

    - [Updating & Migrating](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#updating-migrating)
    - [General](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#general)
    - [RBAC & Users](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#rbac-users)
    - [STIGS & FIPS](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#stigs-fips)
    - [AWS](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#aws)
    - [Azure](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#azure)
    - [Kubernetes](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#kubernetes)
    - [GCP](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#gcp)
    - [API](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#api)
    - [Legacy Docker-based deployments](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#legacy-docker-based-deployments)
    - [AI](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#ai)

[![Chill listening crop-3](https://support.hyperglance.com/hs-fs/hubfs/hyperglance.png?width=134&height=24&name=hyperglance.png "Chill listening crop-3")](https://www.hyperglance.com/)

2880 Zanker Road, Suite 203, San Jose, CA 95134

<https://www.linkedin.com/company/hyperglance/>

Copyright © 2025 Hyperglance. All rights reserved.