Permissions required to map an AWS environment

Collecting data on AWS entities

To collect details on the entities in your AWS environment, we require the following permissions:

AWS API permissions:

   "Version": "2012-10-17",                             
   "Statement": [                                        
      "Sid": "FaddomAWSDiscoveryPermissions",           
        "Effect": "Allow",                               
        "Action": [                                      
      "s3:ListAllMyBuckets"          ],                                             
          "Resource": "*"                                



VPC Flow Logs Permissions

If you enabled VPC Flow Logs to allow Faddom to map the dependencies between the entities in your account, we need the following permissions:

   "Version": "2012-10-17",
   "Statement": [
        "Sid": "FaddomS3Permissions",           
        "Effect": "Allow",                               
        "Action": [                             
       "Resource": [

* Note: replace {FLOW_LOGS_BUCKET} with the bucket name to which flow logs are stored


