docs/source/_static/managed-policies/CloudFormationStackSetsOrgAdminServiceRolePolicy.json
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowsAWSOrganizationsReadAPIs",
"Effect": "Allow",
"Action": [
"organizations:List*",
"organizations:Describe*"
],
"Resource": "*"
},
{
"Sid": "AllowAssumeRoleInMemberAccounts",
"Effect": "Allow",
"Action": "sts:AssumeRole",
"Resource": "arn:aws:iam::*:role/stacksets-exec-*"
}
]
}