| airflow:ListEnvironments | List all MWAA environment names. | 
| airflow:GetEnvironment | Get information about a MWAA environment. | 
| appsync:ListGraphqlApis | List all GraphQL Apis. | 
| batch:DescribeJobDefinitions | List all Batch job definitions. | 
| cloudfront:GetDistributionConfig | Get the name of the S3 bucket containing CloudFront access logs. | 
| cloudfront:ListDistributions | List all CloudFront distributions. | 
| cloudtrail:GetTrail | Get Trail logging information. | 
| cloudtrail:ListTrails | List all Cloudtrail trails. | 
| codebuild:BatchGetProjects | List all CodeBuild projects. | 
| codebuild:ListProjects | Get information on CodeBuild projects. | 
| dms:DescribeReplicationInstances | List all replication instances for DMS. | 
| ec2:DescribeFlowLogs | List all Flow log configurations. | 
| ec2:DescribeVerifiedAccessInstanceLoggingConfigurations | List all Verified Access instance logging configurations. | 
| ec2:DescribeVpnConnections | List all VPN connections. | 
| ecs:DescribeTaskDefinition | Describe ECS task definition. | 
| ecs:ListTaskDefinitionFamilies | List all task definition families. | 
| elasticloadbalancing:
 DescribeLoadBalancers | List all load balancers. | 
| elasticloadbalancing:
 DescribeLoadBalancerAttributes | Get the name of the S3 bucket containing ELB access logs. | 
| eks:DescribeCluster | Describe an EKS cluster. | 
| eks:ListClusters | List all EKS clusters. | 
| lambda:InvokeFunction | Invoke a Lambda function. | 
| lambda:List* | List all Lambda functions. | 
| lambda:GetPolicy | Get the Lambda policy when triggers are to be removed. | 
| logs:PutSubscriptionFilter | Add a Lambda trigger based on CloudWatch Log events. | 
| logs:DeleteSubscriptionFilter | Remove a Lambda trigger based on CloudWatch Log events. | 
| logs:DescribeLogGroups | Describe CloudWatch log groups. | 
| logs:DescribeSubscriptionFilters | List the subscription filters for the specified log group. | 
| network-firewall:DescribeLoggingConfiguration | Get the logging configuration of a firewall. | 
| network-firewall:ListFirewalls | List all Network Firewall firewalls. | 
| rds:DescribeDBClusters | List all RDS clusters. | 
| rds:DescribeDBInstances | List all RDS instances. | 
| redshift:DescribeClusters | List all Redshift clusters. | 
| redshift:DescribeLoggingStatus | Get the name of the S3 bucket containing Redshift Logs. | 
| redshift-serverless:ListNamespaces | List all Redshift Serverless namespaces. | 
| route53:ListQueryLoggingConfigs | List all DNS query logging configurations for Route 53. | 
| route53resolver:ListResolverQueryLogConfigs | List all Resolver query logging configurations for Route 53. | 
| s3:GetBucketLogging | Get the name of the S3 bucket containing S3 access logs. | 
| s3:GetBucketLocation | Get the region of the S3 bucket containing S3 access logs. | 
| s3:GetBucketNotification | Get existing Lambda trigger configurations. | 
| s3:ListAllMyBuckets | List all S3 buckets. | 
| s3:PutBucketNotification | Add or remove a Lambda trigger based on S3 bucket events. | 
| ssm:GetServiceSetting | Get the SSM service setting for customer script log group name. | 
| ssm:ListCommands | List all SSM commands. | 
| states:ListStateMachines | List all Step Functions. | 
| states:DescribeStateMachine | Get logging details about a Step Function. | 
| wafv2:ListLoggingConfigurations | List all logging configurations of the Web Application Firewall. |