Verified Permissions
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for Verified Permissions rules that match the service but not a specific eventName. | N | N |
| Batch | Retrieves information about a group (batch) of policies. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Batch | Makes a series of decisions about multiple authorization requests for one principal or resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Batch | Makes a series of decisions about multiple authorization requests for one token. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Adds an identity source to a policy store-an Amazon Cognito user pool or OpenID Connect (OIDC) identity provider (IdP). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates a Cedar policy and saves it in the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates a policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates a policy store alias for the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates a policy template. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes an identity source that references an identity provider (IdP) such as Amazon Cognito. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes the specified policy from the policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes the specified policy store alias. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes the specified policy template from the policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves the details about the specified identity source. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | Retrieves information about the specified policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves details about a policy store. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | Retrieves details about the specified policy store alias. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieve the details for the specified policy template in the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieve the details for the specified schema in the specified policy store. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Is | Makes an authorization decision about a service request described in the parameters. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Is | Makes an authorization decision about a service request described in the parameters. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Returns a paginated list of all of the identity sources defined in the specified policy store. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Returns a paginated list of all policies stored in the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Returns a paginated list of all policy store aliases in the calling Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Returns a paginated list of all policy stores in the calling Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Returns a paginated list of all policy templates in the specified policy store. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Returns the tags associated with the specified Amazon Verified Permissions resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Put | Creates or updates the policy schema in the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Tag | Assigns one or more tags (key-value pairs) to the specified Amazon Verified Permissions resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Untag | Removes one or more tags from the specified Amazon Verified Permissions resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates the specified identity source to use a new identity provider (IdP), or to change the mapping of identities from the IdP to a different principal entity type. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Update | Modifies a Cedar static policy in the specified policy store. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Update | Modifies the validation setting for a policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates the specified policy template. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
any: Verified Permissions (catch-all)
#Description
Catch-all entry for Verified Permissions rules that match the service but not a specific eventName.
BatchGetPolicy
#Description
Retrieves information about a group (batch) of policies. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateIdentitySource
#Description
Adds an identity source to a policy store-an Amazon Cognito user pool or OpenID Connect (OIDC) identity provider (IdP). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreatePolicy
#Description
Creates a Cedar policy and saves it in the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreatePolicyStore
#Description
Creates a policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreatePolicyStoreAlias
#Description
Creates a policy store alias for the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreatePolicyTemplate
#Description
Creates a policy template. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteIdentitySource
#Description
Deletes an identity source that references an identity provider (IdP) such as Amazon Cognito. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeletePolicy
#Description
Deletes the specified policy from the policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeletePolicyStore
#Description
Deletes the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeletePolicyStoreAlias
#Description
Deletes the specified policy store alias. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeletePolicyTemplate
#Description
Deletes the specified policy template from the policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetIdentitySource
#Description
Retrieves the details about the specified identity source. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a1883edc-ed5f-4797-85d3-2e3f2f401698",
"eventSource": "verifiedpermissions.amazonaws.com",
"eventName": "GetIdentitySource",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "838cc0cd-4ee4-47b1-8050-bc7e3f23ba71",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.8 (+https://www.terraform.io) terraform-provider-aws/6.55.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.1 ua/2.1 os/macos lang/go#1.26.5 md/GOOS#darwin md/GOARCH#arm64 api/verifiedpermissions#1.35.1 m/r,t,u",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::VerifiedPermissions::PolicyStore",
"ARN": "arn:aws:verifiedpermissions::123456789012:policy-store/EXAMPLE"
}
]
}
GetPolicy
#Description
Retrieves information about the specified policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetPolicyStore
#Description
Retrieves details about a policy store. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "76e15f4f-50a9-4022-9808-c41d4e68f26d",
"eventSource": "verifiedpermissions.amazonaws.com",
"eventName": "GetPolicyStore",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "202032c8-b301-4e42-b02e-13ec95655239",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::VerifiedPermissions::PolicyStore",
"ARN": "arn:aws:verifiedpermissions::123456789012:policy-store/EXAMPLE"
}
]
}
GetPolicyStoreAlias
#Description
Retrieves details about the specified policy store alias. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetPolicyTemplate
#Description
Retrieve the details for the specified policy template in the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetSchema
#Description
Retrieve the details for the specified schema in the specified policy store. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "4478fad1-596c-4e29-ac77-24cbbd678824",
"eventSource": "verifiedpermissions.amazonaws.com",
"eventName": "GetSchema",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "1a302f1b-8718-482b-b006-a7f044532340",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::VerifiedPermissions::PolicyStore",
"ARN": "arn:aws:verifiedpermissions::123456789012:policy-store/EXAMPLE"
}
]
}
ListIdentitySources
#Description
Returns a paginated list of all of the identity sources defined in the specified policy store. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "3025f9ea-c57d-4f06-b23d-fed4c6135371",
"eventSource": "verifiedpermissions.amazonaws.com",
"eventName": "ListIdentitySources",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "ed343049-66b5-42dc-a585-912c6a37513f",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::VerifiedPermissions::PolicyStore",
"ARN": "arn:aws:verifiedpermissions::123456789012:policy-store/EXAMPLE"
}
]
}
ListPolicies
#Description
Returns a paginated list of all policies stored in the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListPolicyStoreAliases
#Description
Returns a paginated list of all policy store aliases in the calling Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "4578fcbd-67d5-445b-bc99-b62b74fd19ff",
"eventSource": "verifiedpermissions.amazonaws.com",
"eventName": "ListPolicyStoreAliases",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "afd85420-291d-447d-8352-c73d09026d80",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
}
ListPolicyStores
#Description
Returns a paginated list of all policy stores in the calling Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "11bc59df-224b-4ee6-8dda-ac704feca60e",
"eventSource": "verifiedpermissions.amazonaws.com",
"eventName": "ListPolicyStores",
"awsRegion": "ap-southeast-4",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "1ac33944-eb9e-4afb-8b3d-11c52a00fb26",
"userAgent": "aws-sdk-java/2.46.12 md/io#sync md/http#Apache ua/2.1 api/VerifiedPermissions#2.46.x os/Linux#5.10.255-259-299.1043.amzn2.x86_64 lang/java#17.0.19 md/OpenJDK_64-Bit_Server_VM#17.0.19+10-LTS md/vendor#Amazon.com_Inc. md/en_US exec-env/AWS_Lambda_java17 m/D,AJ,e"
}
ListPolicyTemplates
#Description
Returns a paginated list of all policy templates in the specified policy store. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "b8ddc7e8-5587-4038-a4c1-4360ec46195a",
"eventSource": "verifiedpermissions.amazonaws.com",
"eventName": "ListPolicyTemplates",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "f571a1d1-87d2-4a27-9751-44b7d9957a87",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::VerifiedPermissions::PolicyStore",
"ARN": "arn:aws:verifiedpermissions::123456789012:policy-store/EXAMPLE"
}
]
}
PutSchema
#Description
Creates or updates the policy schema in the specified policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
TagResource
#Description
Assigns one or more tags (key-value pairs) to the specified Amazon Verified Permissions resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UntagResource
#Description
Removes one or more tags from the specified Amazon Verified Permissions resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdateIdentitySource
#Description
Updates the specified identity source to use a new identity provider (IdP), or to change the mapping of identities from the IdP to a different principal entity type. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d15a213f-65c8-459c-8925-8523da325413",
"eventSource": "verifiedpermissions.amazonaws.com",
"eventName": "UpdateIdentitySource",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "256ed3eb-6526-4630-b74e-557443168ba2",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.8 (+https://www.terraform.io) terraform-provider-aws/6.55.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.1 ua/2.1 os/macos lang/go#1.26.5 md/GOOS#darwin md/GOARCH#arm64 api/verifiedpermissions#1.35.1 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::VerifiedPermissions::PolicyStore",
"ARN": "arn:aws:verifiedpermissions::123456789012:policy-store/EXAMPLE"
}
]
}
UpdatePolicy
#Description
Modifies a Cedar static policy in the specified policy store. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "afaca674-c84a-45f9-9640-25d9c0389aac",
"eventSource": "verifiedpermissions.amazonaws.com",
"eventName": "UpdatePolicy",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "edd46aaa-f186-4b17-96f8-2260c681a041",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.8 (+https://www.terraform.io) terraform-provider-aws/6.55.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.1 ua/2.1 os/macos lang/go#1.26.5 md/GOOS#darwin md/GOARCH#arm64 api/verifiedpermissions#1.35.1 m/g",
"errorCode": "ValidationException",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::VerifiedPermissions::PolicyStore",
"ARN": "arn:aws:verifiedpermissions::123456789012:policy-store/EXAMPLE"
}
]
}
UpdatePolicyStore
#Description
Modifies the validation setting for a policy store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdatePolicyTemplate
#Description
Updates the specified policy template. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.