AWS End User Messaging (end-user-messaging)

2026-10-08

27 new actions, 2 new resources, 3 new conditions

Additions

    Actions
  • CreateBrandProfile
    • Description:  Grants permission to create a brand profile
    • Access:  Write
    • Conditions: 

      aws:RequestTag/${TagKey}

      aws:TagKeys

  • CreateBrandProfileAttributes
    • Description:  Grants permission to create attributes for a brand profile
    • Access:  Write
    • Resources: 

      Name: brand-profile

      Required: Yes

  • CreateBrandProfileFromRegistration
    • Description:  Grants permission to create a new brand profile populated from an existing registration via Bedrock mapping
    • Access:  Write
    • Conditions: 

      aws:RequestTag/${TagKey}

      aws:TagKeys

  • CreateNotifyCodeConfiguration
    • Description:  Grants permission to create a notify code configuration
    • Access:  Write
    • Conditions: 

      aws:RequestTag/${TagKey}

      aws:TagKeys

  • CreateRegistrationsFromBrandProfile
    • Description:  Grants permission to create DRAFT registrations pre-filled from brand profile attributes via Bedrock mapping
    • Access:  Write
    • Resources: 

      Name: brand-profile

      Required: Yes

  • DeleteBrandProfile
    • Description:  Grants permission to delete a brand profile
    • Access:  Write
    • Resources: 

      Name: brand-profile

      Required: Yes

  • DeleteBrandProfileAttribute
    • Description:  Grants permission to delete a brand profile attribute
    • Access:  Write
    • Resources: 

      Name: brand-profile

      Required: Yes

  • DeleteNotifyCodeConfiguration
    • Description:  Grants permission to delete a notify code configuration
    • Access:  Write
    • Resources: 

      Name: notify-code-configuration

      Required: Yes

  • GetBrandProfile
    • Description:  Grants permission to get a brand profile
    • Access:  Read
    • Resources: 

      Name: brand-profile

      Required: Yes

  • GetBrandProfileAttribute
    • Description:  Grants permission to get a brand profile attribute
    • Access:  Read
    • Resources: 

      Name: brand-profile

      Required: Yes

  • GetJob
    • Description:  Grants permission to get the details of an asynchronous job
    • Access:  Read
  • GetNotifyCodeConfiguration
    • Description:  Grants permission to get a notify code configuration
    • Access:  Read
    • Resources: 

      Name: notify-code-configuration

      Required: Yes

  • ListBrandProfileAttributes
    • Description:  Grants permission to list the attributes for a brand profile
    • Access:  List
    • Resources: 

      Name: brand-profile

      Required: Yes

  • ListBrandProfiles
    • Description:  Grants permission to list brand profiles
    • Access:  List
  • ListJobs
    • Description:  Grants permission to list asynchronous jobs in your account
    • Access:  List
  • ListNotifyCodeConfigurations
    • Description:  Grants permission to list notify code configurations
    • Access:  List
  • ListRegistrationsFromBrandProfile
    • Description:  Grants permission to list the registrations created from a brand profile
    • Access:  List
    • Resources: 

      Name: brand-profile

      Required: Yes

  • ListTagsForResource
    • Description:  Grants permission to list tags for a resource
    • Access:  Read
    • Resources: 

      Name: brand-profile

      Required: No

      Name: notify-code-configuration

      Required: No

  • SendNotifyCodeVerification
    • Description:  Grants permission to send a notify code verification
    • Access:  Write
    • Resources: 

      Name: notify-code-configuration

      Required: No

  • TagResource
    • Description:  Grants permission to tag a resource
    • Access:  Tagging
    • Resources: 

      Name: brand-profile

      Required: No

      Name: notify-code-configuration

      Required: No

    • Conditions: 

      aws:RequestTag/${TagKey}

      aws:ResourceTag/${TagKey}

      aws:TagKeys

  • UntagResource
    • Description:  Grants permission to untag a resource
    • Access:  Tagging
    • Resources: 

      Name: brand-profile

      Required: No

      Name: notify-code-configuration

      Required: No

    • Conditions: 

      aws:ResourceTag/${TagKey}

      aws:TagKeys

  • UpdateBrandProfile
    • Description:  Grants permission to update a brand profile
    • Access:  Write
    • Resources: 

      Name: brand-profile

      Required: Yes

  • UpdateBrandProfileAttribute
    • Description:  Grants permission to update a brand profile attribute
    • Access:  Write
    • Resources: 

      Name: brand-profile

      Required: Yes

  • UpdateBrandProfileFromRegistration
    • Description:  Grants permission to update a brand profile from a registration
    • Access:  Write
    • Resources: 

      Name: brand-profile

      Required: Yes

  • UpdateNotifyCodeConfiguration
    • Description:  Grants permission to update a notify code configuration
    • Access:  Write
    • Resources: 

      Name: notify-code-configuration

      Required: Yes

  • UpdateRegistrationsFromBrandProfile
    • Description:  Grants permission to update registrations from a brand profile
    • Access:  Write
    • Resources: 

      Name: brand-profile

      Required: Yes

  • ValidateNotifyCodeVerification
    • Description:  Grants permission to validate a notify code verification
    • Access:  Write
    Resources
  • brand-profile
    • Arn:  arn:${Partition}:end-user-messaging:${Region}:${Account}:brand-profile/${ResourceId}
    • Conditions: 

      aws:ResourceTag/${TagKey}

  • notify-code-configuration
    • Arn:  arn:${Partition}:end-user-messaging:${Region}:${Account}:notify-code-configuration/${ResourceId}
    • Conditions: 

      aws:ResourceTag/${TagKey}

    Conditions
  • aws:RequestTag/${TagKey}
    • Description:  Filters access by the tags that are passed in the request
    • Type:  String
  • aws:ResourceTag/${TagKey}
    • Description:  Filters access by the tags attached to the resource
    • Type:  String
  • aws:TagKeys
    • Description:  Filters access by the tag keys that are passed in the request
    • Type:  ArrayOfString