Actions, resources, and condition keys for Amazon Comprehend Medical - Service Authorization Reference

Actions, resources, and condition keys for Amazon Comprehend Medical

Amazon Comprehend Medical (service prefix: comprehendmedical) provides the following service-specific resources, actions, and condition context keys for use in IAM permission policies.

References:

Actions defined by Amazon Comprehend Medical

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

The Resource types column of the Actions table indicates whether each action supports resource-level permissions. If there is no value for this column, you must specify all resources ("*") to which the policy applies in the Resource element of your policy statement. If the column includes a resource type, then you can specify an ARN of that type in a statement with that action. If the action has one or more required resources, the caller must have permission to use the action with those resources. Required resources are indicated in the table with an asterisk (*). If you limit resource access with the Resource element in an IAM policy, you must include an ARN or pattern for each required resource type. Some actions support multiple resource types. If the resource type is optional (not indicated as required), then you can choose to use one of the optional resource types.

The Condition keys column of the Actions table includes keys that you can specify in a policy statement's Condition element. For more information on the condition keys that are associated with resources for the service, see the Condition keys column of the Resource types table.

Note

Resource condition keys are listed in the Resource types table. You can find a link to the resource type that applies to an action in the Resource types (*required) column of the Actions table. The resource type in the Resource types table includes the Condition keys column, which are the resource condition keys that apply to an action in the Actions table.

For details about the columns in the following table, see Actions table.

Actions Description Access level Resource types (*required) Condition keys Dependent actions
DescribeEntitiesDetectionV2Job Grants permission to describe the properties of a medical entity detection job that you have submitted Read
DescribeICD10CMInferenceJob Grants permission to describe the properties of an ICD-10-CM linking job that you have submitted Read
DescribePHIDetectionJob Grants permission to describe the properties of a PHI entity detection job that you have submitted Read
DescribeRxNormInferenceJob Grants permission to describe the properties of an RxNorm linking job that you have submitted Read
DescribeSNOMEDCTInferenceJob Grants permission to describe the properties of a SNOMED-CT linking job that you have submitted Read
DetectEntitiesV2 Grants permission to detect the named medical entities, and their relationships and traits within the given text document Read
DetectPHI Grants permission to detect the protected health information (PHI) entities within the given text document Read
InferICD10CM Grants permission to detect the medical condition entities within the given text document and link them to ICD-10-CM codes Read
InferRxNorm Grants permission to detect the medication entities within the given text document and link them to RxCUI concept identifiers from the National Library of Medicine RxNorm database Read
InferSNOMEDCT Grants permission to detect the medical condition, anatomy, and test, treatment, and procedure entities within the given text document and link them to SNOMED-CT codes Read
ListEntitiesDetectionV2Jobs Grants permission to list the medical entity detection jobs that you have submitted Read
ListICD10CMInferenceJobs Grants permission to list the ICD-10-CM linking jobs that you have submitted Read
ListPHIDetectionJobs Grants permission to list the PHI entity detection jobs that you have submitted Read
ListRxNormInferenceJobs Grants permission to list the RxNorm linking jobs that you have submitted Read
ListSNOMEDCTInferenceJobs Grants permission to list the SNOMED-CT linking jobs that you have submitted Read
StartEntitiesDetectionV2Job Grants permission to start an asynchronous medical entity detection job for a collection of documents Write
StartICD10CMInferenceJob Grants permission to start an asynchronous ICD-10-CM linking job for a collection of documents Write
StartPHIDetectionJob Grants permission to start an asynchronous PHI entity detection job for a collection of documents Write
StartRxNormInferenceJob Grants permission to start an asynchronous RxNorm linking job for a collection of documents Write
StartSNOMEDCTInferenceJob Grants permission to start an asynchronous SNOMED-CT linking job for a collection of documents Write
StopEntitiesDetectionV2Job Grants permission to stop a medical entity detection job Write
StopICD10CMInferenceJob Grants permission to stop an ICD-10-CM linking job Write
StopPHIDetectionJob Grants permission to stop a PHI entity detection job Write
StopRxNormInferenceJob Grants permission to stop an RxNorm linking job Write
StopSNOMEDCTInferenceJob Grants permission to stop a SNOMED-CT linking job Write

Resource types defined by Amazon Comprehend Medical

Amazon Comprehend Medical does not support specifying a resource ARN in the Resource element of an IAM policy statement. To allow access to Amazon Comprehend Medical, specify "Resource": "*" in your policy.

Condition keys for Amazon Comprehend Medical

Amazon Comprehend Medical defines the following condition keys that can be used in the Condition element of an IAM policy. You can use these keys to further refine the conditions under which the policy statement applies. For details about the columns in the following table, see Condition keys table.

To view the global condition keys that are available to all services, see Available global condition keys.

Condition keys Description Type
aws:TagKeys Filters access by the presence of tag keys in the request ArrayOfString