AWS Security ChangesHomeSearch

AWS omics: Document session policies to scope down HealthOmics run permissions

Service: omics · 2026-09-27 · Documentation high

File: omics/latest/dev/permissions-service.md · Type: iam

Summary

Adds an example service role policy for publishing run metrics to CloudWatch and a new section on using inline IAM session policies with the StartRun API/DefaultRunSetting to scope down a run's effective permissions, including an example least-privilege session policy for S3 and CloudWatch Logs.

Security assessment

The added section documents an AWS authorization control that intersects a service role's permissions with a per-run inline session policy, explicitly recommending per-run restriction of sensitive resources (e.g., S3 prefixes) and noting session policies can only restrict, never expand, permissions. This is IAM least-privilege/authorization-scoping guidance with direct security impact.

Evidence

You can use session policies to further restrict the permissions granted by a service role for individual workflow runs. Session policies are inline IAM policies that you provide when starting a run. The effective permissions for the run are the intersection of the service role's permissions and the session policy.

Diff

diff --git a/omics/latest/dev/permissions-service.md b/omics/latest/dev/permissions-service.md
index ccc7966a6..b29a9cb1a 100644
--- a//omics/latest/dev/permissions-service.md
+++ b//omics/latest/dev/permissions-service.md
@@ -7 +7 @@
-Example IAM service policiesExample CloudFormation template
+Example IAM service policiesUse session policies to scope down permissionsExample CloudFormation template
@@ -43,0 +44,2 @@ The trust policy allows the HealthOmics service to assume the role.
+  * Use session policies to scope down permissions
+
@@ -162,0 +165,66 @@ JSON
+The following example shows the policy for a service role that publishes run metrics to CloudWatch. For more information, see [Run metrics for Private Workflows](./monitoring-run-metrics.html).
+
+###### Example Service role policy for run metrics
+    
+    
+    {
+      "Version": "2012-10-17",
+      "Statement": [
+        {
+          "Effect": "Allow",
+          "Action": "cloudwatch:PutMetricData",
+          "Resource": "*"
+        }
+      ]
+    }
+
+## Use session policies to scope down permissions
+
+You can use session policies to further restrict the permissions granted by a service role for individual workflow runs. Session policies are inline IAM policies that you provide when starting a run. The effective permissions for the run are the intersection of the service role's permissions and the session policy.
+
+Session policies are useful when you want to:
+
+  * Grant temporary access to specific Amazon S3 buckets or objects for a single run
+
+  * Restrict access to sensitive resources on a per-run basis
+
+  * Apply additional security controls without modifying the service role
+
+
+
+
+###### Important
+
+Session policies can only restrict permissions; they cannot grant permissions beyond what the service role already allows. The session policy must include permissions for Amazon CloudWatch Logs (`logs:CreateLogStream` and `logs:PutLogEvents`) because HealthOmics uses the run's credentials to create and write to log groups.
+
+Session policies have a maximum length of 2,048 characters and must be valid JSON documents. For more information about session policies, see [Session policies](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_session) in the _IAM User Guide_.
+
+###### Example Session policy for a workflow run
+
+The following example shows a session policy that restricts a run to access only a specific Amazon S3 prefix for output and requires CloudWatch Logs permissions:
+    
+    
+    {
+      "Version": "2012-10-17",
+      "Statement": [
+        {
+          "Effect": "Allow",
+          "Action": [
+            "s3:PutObject",
+            "s3:GetObject"
+          ],
+          "Resource": "arn:aws:s3:::my-bucket/workflow-outputs/run-123/*"
+        },
+        {
+          "Effect": "Allow",
+          "Action": [
+            "logs:CreateLogStream",
+            "logs:PutLogEvents"
+          ],
+          "Resource": "arn:aws:logs:*:*:log-group:/aws/omics/WorkflowLog:*"
+        }
+      ]
+    }
+
+You can specify a session policy when starting a run using the HealthOmics API. The `StartRun` API includes a `sessionPolicy` parameter where you provide the inline policy as a JSON string. For batch runs, you can specify a session policy in the `DefaultRunSetting` that applies to all runs in the batch.
+