Start from a ready-made statement, then tweak it in the Custom builder below
arn:aws:s3:::my-app-bucket/*Guided mode uses friendly permission profiles. Custom Form gives you direct control over Effect, Principal, Action, Resource, and Condition — valid AWS ARN syntax throughout.
Metadata shared by the whole policy document
Allow or Deny the actions below
Choose what people are allowed to do
Hand-pick the exact actions to allow
Control the audience, WhatsApp-privacy style
Files and folders this statement applies to
Deny always overrides an Allow anywhere else in the policy
Who this statement applies to
Real s3: actions this statement covers
Built as arn:aws:s3:::{Bucket}/{Resource}
* for the whole bucket).e.g. require HTTPS, restrict by IP, restrict by principal
This editor is fully editable. Add extra statements by hand, or use + Add Statement above the form — the form always edits the active statement.