View a markdown version of this page

AWS managed policies for CloudWatch Omni - Amazon CloudWatch

AWS managed policies for CloudWatch Omni

CloudWatch Omni provides AWS managed policies for the space operator role, for the domain access role of an organization domain, and for the roles that support organization-level Context Graph enablement. Each policy's details — the description, what it attaches to, the version history, and the complete JSON policy document — are published in the AWS Managed Policy Reference, which is generated from the policy itself and updated automatically when a policy changes. The following table links to each policy's page there.

For guidance on which policy you need for which task, which permissions read across your whole account, and the permissions you provide yourself, see IAM policies to use CloudWatch Omni.

The policies

Policy What it grants
CloudWatchOmniSpaceAccessPolicy The base policy, always attached to the space operator role. The space experience (space and access-grant management, telemetry queries, the context graph, alerts, dashboards, access profiles, views, threads, and integrations), together with the management side of evaluation.
CloudWatchOmniModelInferencePolicy Model inference only. Attached only to spaces that use the prompt playground or run evaluations that invoke a model.
CloudWatchOmniDomainAccessPolicy Domain management for an organization domain. Attached to the domain access role, which CloudWatch Omni assumes to operate the domain. The role is created in the management account during organization domain setup. Single-account domains do not use it.
CloudWatchOmniAWSIntegrationPolicy Resource discovery for Context Graph: lets CloudWatch Omni discover resources and their relationships in an account. Optional on the space operator role — you choose it during space setup. In an organization Centralization rule, CloudWatch Omni also attaches it to the integration roles it provisions in each source account.
AWSCloudWatchOmniServiceRolePolicy Attached to the AWSServiceRoleForCloudWatch_Omni service-linked role, which provisions the integration roles and the AWS Config recorder in member accounts. You cannot attach it to your own identities.

CloudWatch Omni updates to AWS managed policies

The following table describes updates to CloudWatch Omni's AWS managed policies.

Change Description Date
CloudWatchOmniSpaceAccessPolicy — New policy CloudWatch Omni added a policy that grants the space experience — space and access-grant management, telemetry queries, alerts, dashboards, access profiles, views, threads, and integrations — together with the management side of evaluation. September 22, 2026
CloudWatchOmniModelInferencePolicy — New policy CloudWatch Omni added a policy that grants model inference for the prompt playground and for evaluations that invoke a model. September 22, 2026
CloudWatchOmniDomainAccessPolicy — New policy CloudWatch Omni added a policy that grants domain management for an organization domain, attached to the domain access role created during organization domain setup. September 22, 2026
CloudWatchOmniAWSIntegrationPolicy — New policy CloudWatch Omni added a policy that grants resource discovery for Context Graph. It is optional on the space operator role, and CloudWatch Omni attaches it to the integration roles it provisions in the source accounts of an organization Centralization rule. September 22, 2026
AWSCloudWatchOmniServiceRolePolicy — New policy CloudWatch Omni added a policy for the AWSServiceRoleForCloudWatch_Omni service-linked role, which provisions the integration roles and the AWS Config recorder in member accounts. September 22, 2026
CloudWatch Omni started tracking changes CloudWatch Omni started tracking changes for its AWS managed policies. September 22, 2026