Permission sets
A permission set is a template that you create and maintain that defines a collection
of one or more IAM
policies
IAM Identity Center assigns access to a user or group in one or more Amazon Web Services accounts with permission sets. When you assign a permission set, IAM Identity Center creates corresponding IAM Identity Center-controlled IAM roles in each account, and attaches the policies specified in the permission set to those roles. IAM Identity Center manages the role, and allows the authorized users you’ve defined to assume the role, by using the IAM Identity Center User Portal or Amazon CLI. As you modify the permission set, IAM Identity Center ensures that the corresponding IAM policies and roles are updated accordingly.
You can add Amazon managed policies, customer managed policies, inline policies, and Amazon managed policies for job functions to your permission sets. You can also assign an Amazon managed policy or a customer managed policy as a permissions boundary.
To create a permission set, see Create, manage, and delete permission sets.