---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# About Amazon Web Services API permissions

# About Amazon Web Services API permissions {#ariaid-title1}

* Release version: Yokohama
* 
* Updated May 8, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Cloud Account Management interacts with Amazon Web Services to create and manage subscription accounts.
Note:  
You must establish an AWS service account for Cloud Account Management that is separate from the account for Cloud Discovery.

The following API permissions are required to start a new subscription account in AWS:

* budgets: CreateBudgetAction
* budgets: DescribeBudgetAction
* budgets: ModifyBudget
* budgets: ViewBudget
* organizations: AttachPolicy
* organizations: CreateAccount
* organizations: CloseAccount
* organizations: DescribeAccount
* organizations: DescribePolicy
* organizations: DescribeOrganization
* organizations: DescribeOrganizationalUnit
* organizations: DescribeCreateAccountStatus
* organizations: ListRoots
* organizations: ListAccounts
* organizations: ListTagsForResource
* organizations: ListAWSServiceAccessForOrganization",
* organizations: ListAccounts
* organizations: ListParents
* organizations: ListOrganizationalUnitsForParent
* organizations: MoveAccount
* organizations: TagResource
* iam: GetAccountSummary
* sts: AssumeRole

{#about-aws-api-permissions__ul_tjv_jbd_sbc}  
Note:  
For more details on API permissions, download the [Cloud Discovery REST API permissions spreadsheet](https://downloads.docs.servicenow.com/resource/enus/api/servicenow-discovery-patterns-api-details.xlsx) so you can research and grant the user permissions required for running the discovery process.

