{
  "url": "https://docs.aws.amazon.com/service-authorization/latest/reference/list_cloudwatch.html",
  "name": "Amazon CloudWatch",
  "prefix": "cloudwatch",
  "timestamp": "1786363206",
  "actions": [
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "BatchGetServiceLevelIndicatorReport",
      "description": "Grants permission to batch get service level indicator report",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "BatchGetServiceLevelObjectiveBudgetReport",
      "description": "Grants permission to batch retrieve a service level objective budget report",
      "access": "Read",
      "resources": [
        {
          "name": "slo",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/permissions-reference-cw.html",
      "name": "CallWithBearerToken",
      "description": "Grants permission to make API calls to CloudWatch using bearer token authentication",
      "access": "Write",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "CreateServiceLevelObjective",
      "description": "Grants permission to create a service level objective",
      "access": "Write",
      "resources": [],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DeleteAlarmMuteRule.html",
      "name": "DeleteAlarmMuteRule",
      "description": "Grants permission to delete an alarm mute rule",
      "access": "Write",
      "resources": [
        {
          "name": "alarm-mute-rule",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DeleteAlarms.html",
      "name": "DeleteAlarms",
      "description": "Grants permission to delete a collection of alarms",
      "access": "Write",
      "resources": [
        {
          "name": "alarm",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DeleteAnomalyDetector.html",
      "name": "DeleteAnomalyDetector",
      "description": "Grants permission to delete the specified anomaly detection model from your account",
      "access": "Write",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DeleteDashboards.html",
      "name": "DeleteDashboards",
      "description": "Grants permission to delete all CloudWatch dashboards that you specify",
      "access": "Write",
      "resources": [
        {
          "name": "dashboard",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DeleteInsightRules.html",
      "name": "DeleteInsightRules",
      "description": "Grants permission to delete a collection of insight rules",
      "access": "Write",
      "resources": [
        {
          "name": "insight-rule",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DeleteMetricStream.html",
      "name": "DeleteMetricStream",
      "description": "Grants permission to delete the CloudWatch metric stream that you specify",
      "access": "Write",
      "resources": [
        {
          "name": "metric-stream",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/permissions-reference-cw.html",
      "name": "DeletePipelineRule",
      "description": "Grants permission to delete a pipeline rule for CloudWatch pipelines for OTel metric processing",
      "access": "Write",
      "resources": [
        {
          "name": "dataset",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "DeleteServiceLevelObjective",
      "description": "Grants permission to delete a service level objective",
      "access": "Write",
      "resources": [
        {
          "name": "slo",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DescribeAlarmHistory.html",
      "name": "DescribeAlarmHistory",
      "description": "Grants permission to retrieve the history for the specified alarm",
      "access": "Read",
      "resources": [
        {
          "name": "alarm",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DescribeAlarms.html",
      "name": "DescribeAlarms",
      "description": "Grants permission to describe all alarms, currently owned by the user's account",
      "access": "Read",
      "resources": [
        {
          "name": "alarm",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DescribeAlarmsForMetric.html",
      "name": "DescribeAlarmsForMetric",
      "description": "Grants permission to describe all alarms configured on the specified metric, currently owned by the user's account",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DescribeAnomalyDetectors.html",
      "name": "DescribeAnomalyDetectors",
      "description": "Grants permission to list the anomaly detection models that you have created in your account",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DescribeInsightRules.html",
      "name": "DescribeInsightRules",
      "description": "Grants permission to describe all insight rules, currently owned by the user's account",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DisableAlarmActions.html",
      "name": "DisableAlarmActions",
      "description": "Grants permission to disable actions for a collection of alarms",
      "access": "Write",
      "resources": [
        {
          "name": "alarm",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DisableInsightRules.html",
      "name": "DisableInsightRules",
      "description": "Grants permission to disable a collection of insight rules",
      "access": "Write",
      "resources": [
        {
          "name": "insight-rule",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_EnableAlarmActions.html",
      "name": "EnableAlarmActions",
      "description": "Grants permission to enable actions for a collection of alarms",
      "access": "Write",
      "resources": [
        {
          "name": "alarm",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_EnableInsightRules.html",
      "name": "EnableInsightRules",
      "description": "Grants permission to enable a collection of insight rules",
      "access": "Write",
      "resources": [
        {
          "name": "insight-rule",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "EnableTopologyDiscovery",
      "description": "Grants permission to enable a CloudWatch topology discovery",
      "access": "Write",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/cloudwatch-metrics-insights-query-assist.html",
      "name": "GenerateQuery",
      "description": "Grants permission to generate a Metrics Insights or Logs Insights query string from a natural language prompt",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CloudWatchLogs-Insights-Query-Results-Summary.html",
      "name": "GenerateQueryResultsSummary",
      "description": "Grants permission to generate a summary of CloudWatch LogInsights query results in natural language using generative AI",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_GetAlarmMuteRule.html",
      "name": "GetAlarmMuteRule",
      "description": "Grants permission to get an alarm mute rule",
      "access": "Read",
      "resources": [
        {
          "name": "alarm-mute-rule",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_GetDashboard.html",
      "name": "GetDashboard",
      "description": "Grants permission to display the details of the CloudWatch dashboard you specify",
      "access": "Read",
      "resources": [
        {
          "name": "dashboard",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_GetDataset.html",
      "name": "GetDataset",
      "description": "Grants permission to get a dataset",
      "access": "Read",
      "resources": [
        {
          "name": "dataset",
          "is_required": true
        }
      ],
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_GetInsightRuleReport.html",
      "name": "GetInsightRuleReport",
      "description": "Grants permission to return the top-N report of unique contributors over a time range for a given insight rule",
      "access": "Read",
      "resources": [
        {
          "name": "insight-rule",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_GetMetricData.html",
      "name": "GetMetricData",
      "description": "Grants permission to retrieve batch amounts of CloudWatch classic metric data and perform metric math on retrieved data; and grants permission to retrieve OTLP metric data using PromQL",
      "access": "Read",
      "resources": [
        {
          "name": "dataset",
          "is_required": false
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_GetMetricStatistics.html",
      "name": "GetMetricStatistics",
      "description": "Grants permission to retrieve statistics for the specified metric",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_GetMetricStream.html",
      "name": "GetMetricStream",
      "description": "Grants permission to return the details of a CloudWatch metric stream",
      "access": "Read",
      "resources": [
        {
          "name": "metric-stream",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_GetMetricWidgetImage.html",
      "name": "GetMetricWidgetImage",
      "description": "Grants permission to retrieve snapshots of metric widgets",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/permissions-reference-cw.html",
      "name": "GetOTelEnrichment",
      "description": "Grants permission to retrieve the status of OTel Enrichment of vended metrics for PromQL querying",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "GetService",
      "description": "Grants permission to retrieve information about a service",
      "access": "Read",
      "resources": [
        {
          "name": "service",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/permissions-reference-cw.html",
      "name": "GetServiceData",
      "description": "Grants permission to retrieve service data",
      "access": "Read",
      "resources": [
        {
          "name": "service",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "GetServiceLevelObjective",
      "description": "Grants permission to retrieve information about service level objective",
      "access": "Read",
      "resources": [
        {
          "name": "slo",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/permissions-reference-cw.html",
      "name": "GetTopologyDiscoveryStatus",
      "description": "Grants permission to retrieve a CloudWatch topology discovery status",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "GetTopologyMap",
      "description": "Grants permission to retrieve a CloudWatch topology map",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Unified-Cross-Account-Setup.html#CloudWatch-Unified-Cross-Account-Setup-permissions",
      "name": "Link",
      "description": "Grants permission to share CloudWatch resources with a monitoring account",
      "access": "Write",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_ListAlarmMuteRules.html",
      "name": "ListAlarmMuteRules",
      "description": "Grants permission to retrieve a list of alarm mute rules owned by the user's account",
      "access": "List",
      "resources": [
        {
          "name": "alarm-mute-rule",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_ListDashboards.html",
      "name": "ListDashboards",
      "description": "Grants permission to return a list of all CloudWatch dashboards in your account",
      "access": "List",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/permissions-reference-cw.html",
      "name": "ListEntitiesForMetric",
      "description": "Grants permission to retrieve all the entities that are emitting a given metric",
      "access": "List",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_ListManagedInsightRules.html",
      "name": "ListManagedInsightRules",
      "description": "Grants permission to list available managed Insight Rules for a given Resource ARN",
      "access": "Read",
      "resources": [],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "cloudwatch:requestManagedResourceARNs"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_ListMetricStreams.html",
      "name": "ListMetricStreams",
      "description": "Grants permission to return a list of all CloudWatch metric streams in your account",
      "access": "List",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_ListMetrics.html",
      "name": "ListMetrics",
      "description": "Grants permission to retrieve a list of valid metrics stored for the AWS account owner",
      "access": "List",
      "resources": [
        {
          "name": "dataset",
          "is_required": false
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "ListServiceLevelObjectives",
      "description": "Grants permission to list service level objectives",
      "access": "List",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "ListServices",
      "description": "Grants permission to list services",
      "access": "List",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_ListTagsForResource.html",
      "name": "ListTagsForResource",
      "description": "Grants permission to list tags for an Amazon CloudWatch resource",
      "access": "List",
      "resources": [
        {
          "name": "alarm",
          "is_required": false
        },
        {
          "name": "alarm-mute-rule",
          "is_required": false
        },
        {
          "name": "dashboard",
          "is_required": false
        },
        {
          "name": "dataset",
          "is_required": false
        },
        {
          "name": "insight-rule",
          "is_required": false
        },
        {
          "name": "metric-stream",
          "is_required": false
        },
        {
          "name": "service",
          "is_required": false
        },
        {
          "name": "slo",
          "is_required": false
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_PutAlarmMuteRule.html",
      "name": "PutAlarmMuteRule",
      "description": "Grants permission to create or update an alarm mute rule",
      "access": "Write",
      "resources": [
        {
          "name": "alarm",
          "is_required": false
        },
        {
          "name": "alarm-mute-rule",
          "is_required": true
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_PutAnomalyDetector.html",
      "name": "PutAnomalyDetector",
      "description": "Grants permission to create or update an anomaly detection model for a CloudWatch metric",
      "access": "Write",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_PutCompositeAlarm.html",
      "name": "PutCompositeAlarm",
      "description": "Grants permission to create or update a composite alarm",
      "access": "Write",
      "resources": [
        {
          "name": "alarm",
          "is_required": true
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "cloudwatch:AlarmActions"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_PutDashboard.html",
      "name": "PutDashboard",
      "description": "Grants permission to create a CloudWatch dashboard, or update an existing dashboard if it already exists",
      "access": "Write",
      "resources": [
        {
          "name": "dashboard",
          "is_required": true
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_PutInsightRule.html",
      "name": "PutInsightRule",
      "description": "Grants permission to create a new insight rule or replace an existing insight rule",
      "access": "Write",
      "resources": [
        {
          "name": "insight-rule",
          "is_required": true
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "cloudwatch:requestInsightRuleLogGroups"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_PutLogAlarm.html",
      "name": "PutLogAlarm",
      "description": "Grants permission to create or update a log-based alarm and associate it with a CloudWatch Logs Insights scheduled query",
      "access": "Write",
      "resources": [
        {
          "name": "alarm",
          "is_required": true
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "cloudwatch:AlarmActions"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_PutManagedInsightRules.html",
      "name": "PutManagedInsightRules",
      "description": "Grants permission to create managed Insight Rules",
      "access": "Write",
      "resources": [],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "cloudwatch:requestManagedResourceARNs"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_PutMetricAlarm.html",
      "name": "PutMetricAlarm",
      "description": "Grants permission to create or update an alarm and associates it with the specified Amazon CloudWatch metric",
      "access": "Write",
      "resources": [
        {
          "name": "alarm",
          "is_required": true
        },
        {
          "name": "dataset",
          "is_required": false
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "cloudwatch:AlarmActions"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_PutMetricData.html",
      "name": "PutMetricData",
      "description": "Grants permission to publish metric data points to Amazon CloudWatch using CloudWatch and OTLP formats",
      "access": "Write",
      "resources": [
        {
          "name": "dataset",
          "is_required": false
        }
      ],
      "conditions": [
        "cloudwatch:namespace"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_PutMetricStream.html",
      "name": "PutMetricStream",
      "description": "Grants permission to create a CloudWatch metric stream, or update an existing metric stream if it already exists",
      "access": "Write",
      "resources": [
        {
          "name": "metric-stream",
          "is_required": true
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/permissions-reference-cw.html",
      "name": "PutPipelineRule",
      "description": "Grants permission to create or update a pipeline rule for CloudWatch pipelines for OTel metric processing",
      "access": "Write",
      "resources": [
        {
          "name": "dataset",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_SetAlarmState.html",
      "name": "SetAlarmState",
      "description": "Grants permission to temporarily set the state of an alarm for testing purposes",
      "access": "Write",
      "resources": [
        {
          "name": "alarm",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_StartMetricStreams.html",
      "name": "StartMetricStreams",
      "description": "Grants permission to start all CloudWatch metric streams that you specify",
      "access": "Write",
      "resources": [
        {
          "name": "metric-stream",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/permissions-reference-cw.html",
      "name": "StartOTelEnrichment",
      "description": "Grants permission to enable OTel Enrichment of vended metrics for PromQL querying",
      "access": "Write",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_StopMetricStreams.html",
      "name": "StopMetricStreams",
      "description": "Grants permission to stop all CloudWatch metric streams that you specify",
      "access": "Write",
      "resources": [
        {
          "name": "metric-stream",
          "is_required": true
        }
      ],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/permissions-reference-cw.html",
      "name": "StopOTelEnrichment",
      "description": "Grants permission to disable OTel Enrichment of vended metrics for PromQL querying",
      "access": "Write",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_TagResource.html",
      "name": "TagResource",
      "description": "Grants permission to add tags to an Amazon CloudWatch resource",
      "access": "Tagging",
      "resources": [
        {
          "name": "alarm",
          "is_required": false
        },
        {
          "name": "alarm-mute-rule",
          "is_required": false
        },
        {
          "name": "dashboard",
          "is_required": false
        },
        {
          "name": "dataset",
          "is_required": false
        },
        {
          "name": "insight-rule",
          "is_required": false
        },
        {
          "name": "metric-stream",
          "is_required": false
        },
        {
          "name": "service",
          "is_required": false
        },
        {
          "name": "slo",
          "is_required": false
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_UntagResource.html",
      "name": "UntagResource",
      "description": "Grants permission to remove a tag from an Amazon CloudWatch resource",
      "access": "Tagging",
      "resources": [
        {
          "name": "alarm",
          "is_required": false
        },
        {
          "name": "alarm-mute-rule",
          "is_required": false
        },
        {
          "name": "dashboard",
          "is_required": false
        },
        {
          "name": "dataset",
          "is_required": false
        },
        {
          "name": "insight-rule",
          "is_required": false
        },
        {
          "name": "metric-stream",
          "is_required": false
        },
        {
          "name": "service",
          "is_required": false
        },
        {
          "name": "slo",
          "is_required": false
        }
      ],
      "conditions": [
        "aws:TagKeys"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Application-Monitoring-Sections.html#ApplicationSignals-PreviewSDK",
      "name": "UpdateServiceLevelObjective",
      "description": "Grants permission to update a service level objective",
      "access": "Write",
      "resources": [
        {
          "name": "slo",
          "is_required": true
        }
      ],
      "conditions": []
    }
  ],
  "resources": [
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/auth-and-access-control-cw.html",
      "name": "alarm",
      "arn": "arn:${Partition}:cloudwatch:${Region}:${Account}:alarm:${AlarmName}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/auth-and-access-control-cw.html",
      "name": "alarm-mute-rule",
      "arn": "arn:${Partition}:cloudwatch:${Region}:${Account}:alarm-mute-rule:${AlarmMuteRuleName}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/auth-and-access-control-cw.html",
      "name": "dashboard",
      "arn": "arn:${Partition}:cloudwatch::${Account}:dashboard/${DashboardName}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/auth-and-access-control-cw.html",
      "name": "dataset",
      "arn": "arn:${Partition}:cloudwatch:${Region}:${Account}:dataset/${DatasetId}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/auth-and-access-control-cw.html",
      "name": "insight-rule",
      "arn": "arn:${Partition}:cloudwatch:${Region}:${Account}:insight-rule/${InsightRuleName}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/auth-and-access-control-cw.html",
      "name": "metric-stream",
      "arn": "arn:${Partition}:cloudwatch:${Region}:${Account}:metric-stream/${MetricStreamName}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/auth-and-access-control-cw.html",
      "name": "service",
      "arn": "arn:${Partition}:cloudwatch:${Region}:${Account}:service/${ServiceName}-${UniqueAttributesHex}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/auth-and-access-control-cw.html",
      "name": "slo",
      "arn": "arn:${Partition}:cloudwatch:${Region}:${Account}:slo/${SloName}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    }
  ],
  "conditions": [
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-requesttag",
      "name": "aws:RequestTag/${TagKey}",
      "description": "Filters access by the presence of tags in the request",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-resourcetag",
      "name": "aws:ResourceTag/${TagKey}",
      "description": "Filters access by tags associated with the resource",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-tagkeys",
      "name": "aws:TagKeys",
      "description": "Filters access by the presence of tags in the request",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/iam-cw-condition-keys-alarm-actions.html",
      "name": "cloudwatch:AlarmActions",
      "description": "Filters access by defined alarm actions",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/iam-cw-condition-keys-namespace.html",
      "name": "cloudwatch:namespace",
      "description": "Filters access by the presence of optional namespace values",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/iam-cw-condition-keys-contributor.html",
      "name": "cloudwatch:requestInsightRuleLogGroups",
      "description": "Filters access by the Log Groups specified in an Insight Rule",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/iam-cw-condition-keys-contributor.html",
      "name": "cloudwatch:requestManagedResourceARNs",
      "description": "Filters access by the Resource ARNs specified in a managed Insight Rule",
      "type": "ArrayOfARN"
    }
  ]
}