AWS Security ChangesHomeSearch

AWS omics: Batch workflows: session policy mention and run metrics IAM permission

Service: omics · 2026-09-27 · Documentation medium

File: omics/latest/dev/workflows-batch.md · Type: iam

Summary

Adds 'session policy' to the list of parameters in defaultRunSetting, and adds an 'Enable run metrics' section documenting that the batch service role needs cloudwatch:PutMetricData, including a sample IAM policy.

Security assessment

The change documents an IAM permission (cloudwatch:PutMetricData) required by the batch service role and mentions session policies, which are access-control constructs. It is permission/monitoring guidance rather than a fix for a specific vulnerability; the sample policy uses Resource "*", so it is hardening guidance of medium impact.

Evidence

+Run metrics report near real-time resource utilization for the runs in a batch. To enable run metrics, the service role that you use for the batch must have the `cloudwatch:PutMetricData` permission. For more information, see [Run metrics for Private Workflows](./monitoring-run-metrics.html).

Diff

diff --git a/omics/latest/dev/workflows-batch.md b/omics/latest/dev/workflows-batch.md
index 05262e335..d76355470 100644
--- a//omics/latest/dev/workflows-batch.md
+++ b//omics/latest/dev/workflows-batch.md
@@ -63 +63 @@ With batch runs, you can:
-  * **Default run setting** (`defaultRunSetting`) — Workflow parameters shared across all runs in the batch, such as workflow ID, IAM role, output URI, and common parameters.
+  * **Default run setting** (`defaultRunSetting`) — Workflow parameters shared across all runs in the batch, such as workflow ID, IAM role, output URI, session policy, and common parameters.
@@ -694,0 +695,18 @@ Filter | Description
+### Enable run metrics
+
+Run metrics report near real-time resource utilization for the runs in a batch. To enable run metrics, the service role that you use for the batch must have the `cloudwatch:PutMetricData` permission. For more information, see [Run metrics for Private Workflows](./monitoring-run-metrics.html).
+
+Add the following permission to the service role that you use for the batch.
+    
+    
+    {
+      "Version": "2012-10-17",
+      "Statement": [
+        {
+          "Effect": "Allow",
+          "Action": "cloudwatch:PutMetricData",
+          "Resource": "*"
+        }
+      ]
+    }
+