AWS IAM Data Dashboard

Total Number of Services

438

Average actions per Service

43

Median actions per Service

29

# of distinct resource ARNs

1916

# of distinct condition keys

1185

Write actions

10274

Read actions

5004

List actions

3049

Permision actions

346

Services with most actions

Service Name

Action Count

Amazon EC2

Amazon SageMaker

Amazon Chime

AWS Glue

Amazon Connect

AWS IoT

Amazon QuickSight

Amazon Bedrock

Amazon DataZone

AWS Identity and Access Management (IAM)

702

392

316

291

291

287

230

194

185

176

Services with least actions

Service Name

Action Count

AWS CloudTrail Data

AWS Elemental Support Content

AWS IAM Identity Center OIDC service

AWS Marketplace Discovery

AWS Marketplace Entitlement Service

AWS Marketplace Reporting

AWS Marketplace Seller Reporting

AWS Microservice Extractor for .NET

AWS PrivateLink

AWS Sustainability

1

1

1

1

1

1

1

1

1

1

Most referenced resource ARNs

  • instance - arn:${Partition}:connect:${Region}:${Account}:instance/${InstanceId}123
  • organization - arn:${Partition}:workmail:${Region}:${Account}:organization/${ResourceId}122
  • application - arn:${Partition}:qbusiness:${Region}:${Account}:application/${ApplicationId}108
  • directory - arn:${Partition}:ds:${Region}:${Account}:directory/${DirectoryId}88
  • userpool - arn:${Partition}:cognito-idp:${Region}:${Account}:userpool/${UserPoolId}87
  • bot - arn:${Partition}:lex:${Region}:${Account}:bot/${BotId}81
  • repository - arn:${Partition}:codecommit:${Region}:${Account}:${RepositoryName}81
  • rootcatalog - arn:${Partition}:glue:${Region}:${Account}:catalog74
  • domains - arn:${Partition}:profile:${Region}:${Account}:domains/${DomainName}73
  • stack - arn:${Partition}:opsworks:${Region}:${Account}:stack/${StackId}/66

Longest service prefixes

Service prefix

Action Count

license-manager-linux-subscriptions

license-manager-user-subscriptions

partnercentral-account-management

sagemaker-data-science-assistant

route53-recovery-control-config

elemental-appliances-software

marketplacecommerceanalytics

application-transformation

aws-marketplace-management

codedeploy-commands-secure

35

34

33

32

31

29

28

26

26

26

Shortest service prefixes

Service prefix

Length

q

ce

ds

es

iq

m2

mq

pi

s3

ts

1

2

2

2

2

2

2

2

2

2

Longest action names

Action Name

Length

license-manager-linux-subscriptions:ListRegisteredSubscriptionProviders

codecatalyst:BatchDisassociateIdentitiesFromIdentityCenterApplication

license-manager-linux-subscriptions:GetRegisteredSubscriptionProvider

networkflowmonitor:GetQueryResultsWorkloadInsightsTopContributorsData

servicecatalog:BatchDisassociateServiceActionFromProvisioningArtifact

aws-marketplace-management:GetAdditionalSellerNotificationRecipients

aws-marketplace-management:PutAdditionalSellerNotificationRecipients

networkflowmonitor:GetQueryStatusWorkloadInsightsTopContributorsData

servicecatalog:NotifyTerminateProvisionedProductEngineWorkflowResult

bcm-pricing-calculator:ListBillEstimateInputCommitmentModifications

71

69

69

69

69

68

68

68

68

67

Shortest action names

Action Name

Length

dax:Scan

ecs:Poll

kms:Sign

dax:Query

logs:Link

xray:Link

ce:GetTags

es:AddTags

iq:EndCall

iq:GetCall

8

8

8

9

9

9

10

10

10

10

Longest condition key names

Condition key name

Length

codebuild:secondarySources/${sourceIdentifier}.buildStatusConfig.targetUrl

codebuild:secondarySources/${sourceIdentifier}.buildStatusConfig.context

codebuild:secondaryArtifacts/${artifactIdentifier}.encryptionDisabled

codebuild:secondaryArtifacts/${artifactIdentifier}.bucketOwnerAccess

codebuild:secondarySources/${sourceIdentifier}.auth.resource

iot:CommandExecutionParameterBoolean/${CommandParameterName}

payment-cryptography:CertificateAuthorityPublicKeyIdentifier

codebuild:buildBatchConfig.restrictions.computeTypesAllowed

codebuild:environment.registryCredential.credentialProvider

codebuild:secondaryArtifacts/${artifactIdentifier}.location

74

72

69

68

60

60

60

59

59

59

Shortest condition key names

Condition key name

Length

ec2:Vpc

rds:Vpc

saml:cn

ecs:task

saml:aud

saml:doc

saml:iss

saml:sub

saml:uid

swf:name

7

7

7

8

8

8

8

8

8

8