cloudwatch:DescribeAlarms
Literal appearances in AWS managed IAM policies. Statements that use wildcards (for example s3:*) are not counted here. This is not an IAM authorization simulation.
Policies (any)
91
Allow (Action)
91
Deny (Action)
0
NotAction
2
Index generated 4/7/2026, 3:29:24 AM. 559 policies include at least one wildcard action string (any service).
Action reference
SAR-style (unofficial)Service: Amazon CloudWatch
Access level
ReadDescription
Grants permission to describe all alarms, currently owned by the user's account
Resource types
- alarm*
Allow (Action)
- AWSApplicationAutoScalingCustomResourcePolicy
- AWSApplicationAutoscalingAppStreamFleetPolicy
- AWSApplicationAutoscalingCassandraTablePolicy
- AWSApplicationAutoscalingComprehendEndpointPolicy
- AWSApplicationAutoscalingDynamoDBTablePolicy
- AWSApplicationAutoscalingEC2SpotFleetRequestPolicy
- AWSApplicationAutoscalingECSServicePolicy
- AWSApplicationAutoscalingEMRInstanceGroupPolicy
- AWSApplicationAutoscalingElastiCacheRGPolicy
- AWSApplicationAutoscalingKafkaClusterPolicy
- AWSApplicationAutoscalingLambdaConcurrencyPolicy
- AWSApplicationAutoscalingNeptuneClusterPolicy
- AWSApplicationAutoscalingRDSClusterPolicy
- AWSApplicationAutoscalingSageMakerEndpointPolicy
- AWSApplicationAutoscalingWorkSpacesPoolPolicy
- AWSAuditManagerServiceRolePolicy
- AWSCodeDeployRole
- AWSCodeDeployRoleForECS
- AWSCodeDeployRoleForECSLimited
- AWSCodeDeployRoleForLambda
- AWSCodeDeployRoleForLambdaLimited
- AWSConfigRole
- AWSConfigServiceRolePolicy
- AWSElasticBeanstalkReadOnly
- AWSIoTFleetHubFederationAccess
- AWSResilienceHubAsssessmentExecutionPolicy
- AWSResourceExplorerServiceRolePolicy
- AWSSecurityHubServiceRolePolicy
- AWSSystemsManagerChangeManagementServicePolicy
- AWSZonalAutoshiftPracticeRunSLRPolicy
- AWS_ConfigRole
- AWS_Config_Role
- AdministratorAccess-AWSElasticBeanstalk
- AmazonAppStreamFullAccess
- AmazonApplicationRecoveryControllerRegionSwitchPlanExecutionPolicy
- AmazonAthenaFullAccess
- AmazonCloudWatchEvidentlyFullAccess
- AmazonCloudWatchRUMFullAccess
- AmazonCloudWatchRUMReadOnlyAccess
- AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary
- AmazonDevOpsGuruServiceRolePolicy
- AmazonDynamoDBFullAccess
- AmazonDynamoDBFullAccess_v2
- AmazonDynamoDBFullAccesswithDataPipeline
- AmazonDynamoDBReadOnlyAccess
- AmazonEC2ContainerServiceAutoscaleRole
- AmazonEC2SpotFleetAutoscaleRole
- AmazonECSInfrastructureRoleforExpressGatewayServices
- AmazonECSServiceRolePolicy
- AmazonECS_FullAccess
- AmazonEMRServicePolicy_v2
- AmazonElasticMapReduceRole
- AmazonElasticMapReduceforAutoScalingRole
- AmazonFISServiceRolePolicy
- AmazonFSxConsoleFullAccess
- AmazonFSxConsoleReadOnlyAccess
- AmazonGrafanaCloudWatchAccess
- AmazonKeyspacesFullAccess
- AmazonKeyspacesReadOnlyAccess
- AmazonKeyspacesReadOnlyAccess_v2
- AmazonLaunchWizardFullAccessV2
- AmazonLaunchWizardFullaccess
- AmazonLaunchWizard_Fullaccess
- AmazonLexFullAccess
- AmazonMCSFullAccess
- AmazonMCSReadOnlyAccess
- AmazonRDSCustomPreviewServiceRolePolicy
- AmazonRDSCustomServiceRolePolicy
- AmazonRDSFullAccess
- AmazonRoute53FullAccess
- AmazonSSMServiceRolePolicy
- AmazonSageMakerCanvasFullAccess
- AmazonSageMakerFullAccess
- AmazonSageMakerReadOnly
- ApplicationAutoScalingForAmazonAppStreamAccess
- AutoScalingServiceRolePolicy
- CloudWatchApplicationSignalsFullAccess
- CloudWatchApplicationSignalsReadOnlyAccess
- CloudWatchEventsServiceRolePolicy
- CloudWatchSyntheticsFullAccess
- CloudwatchApplicationInsightsServiceLinkedRolePolicy
- ComputeOptimizerServiceRolePolicy
- ConsoleFullAccessFromVercel
- ConsoleViewOnlyAccessFromVercel
- KeyspacesReplicationServiceRolePolicy
- NetworkAdministrator
- Route53RecoveryReadinessServiceRolePolicy
- SageMakerStudioProjectRoleMachineLearningPolicy
- SageMakerStudioProjectUserRolePermissionsBoundary
- ServiceQuotasFullAccess
- ServiceQuotasReadOnlyAccess
Deny (Action)
None
Thanks to Ian McKay for iam-dataset (MIT), structured data derived from the AWS Service Authorization Reference. Not maintained by AWS and not guaranteed current. IAMTrail's managed policy archive is separate.
Definitions bundle generated 4/7/2026, 3:29:24 AM