> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plerion.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Coverage

> The AWS resource types and sharing mechanisms Plerion evaluates for resource access grants

With **[resource access grants](https://app.plerion.com/entitlements/access-grants)**, Plerion evaluates access across a growing set of AWS resource types and sharing mechanisms. This page lists what is evaluated today.

***

## Sharing mechanisms

Plerion detects access through four mechanisms.

| Mechanism           | What it is                                                                                                                                                                                                                                        |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Resource policy** | An IAM-policy-shaped resource-based policy attached to, or scoped to, the resource, such as an S3 bucket policy or a KMS key policy.                                                                                                              |
| **Trust policy**    | An IAM role's `AssumeRolePolicyDocument`, which controls who may assume the role.                                                                                                                                                                 |
| **RAM share**       | An AWS Resource Access Manager (RAM) resource share, evaluated as an equivalent IAM-shaped grant.                                                                                                                                                 |
| **Attribute share** | A cross-account permission set directly on the resource as an attribute, such as an AMI launch permission or an EBS, RDS, or Redshift snapshot restore permission, rather than as a policy document. Evaluated as an equivalent IAM-shaped grant. |

***

## Covered resource types

Coverage expands over time. The **Mechanism** column shows how Plerion evaluates each type: from a resource-based policy, from an IAM role's trust policy, through an AWS Resource Access Manager (RAM) resource share, or from a cross-account permission attribute on the resource.

| Service                                  | Resource                                            | Mechanism       |
| ---------------------------------------- | --------------------------------------------------- | --------------- |
| Amazon S3                                | Bucket                                              | Resource policy |
| Amazon S3                                | Access point                                        | Resource policy |
| Amazon S3                                | Directory bucket (S3 Express One Zone)              | Resource policy |
| Amazon S3                                | Directory bucket access point (S3 Express One Zone) | Resource policy |
| Amazon S3                                | Table bucket (S3 Tables)                            | Resource policy |
| Amazon S3                                | Table (S3 Tables)                                   | Resource policy |
| Amazon S3                                | Vector bucket (S3 Vectors)                          | Resource policy |
| AWS Identity and Access Management (IAM) | Role                                                | Trust policy    |
| AWS Key Management Service (KMS)         | KMS key                                             | Resource policy |
| Amazon SQS                               | Queue                                               | Resource policy |
| Amazon SNS                               | Topic                                               | Resource policy |
| AWS Lambda                               | Function                                            | Resource policy |
| AWS Lambda                               | Layer                                               | Resource policy |
| AWS Secrets Manager                      | Secret                                              | Resource policy |
| Amazon OpenSearch Service                | Domain                                              | Resource policy |
| Amazon EventBridge                       | Event bus                                           | Resource policy |
| Amazon EventBridge                       | Schema registry                                     | Resource policy |
| Amazon SES                               | Email identity                                      | Resource policy |
| AWS Serverless Application Repository    | Application                                         | Resource policy |
| Amazon DynamoDB                          | Table                                               | Resource policy |
| Amazon EFS                               | File system                                         | Resource policy |
| Amazon ECR                               | Repository                                          | Resource policy |
| Amazon ECR                               | Registry                                            | Resource policy |
| Amazon Kinesis Data Streams              | Data stream                                         | Resource policy |
| Amazon SageMaker AI                      | Model package group                                 | Resource policy |
| Amazon Rekognition                       | Project                                             | Resource policy |
| Amazon API Gateway                       | REST API                                            | Resource policy |
| AWS Backup                               | Backup vault                                        | Resource policy |
| AWS CodeBuild                            | Build project                                       | Resource policy |
| AWS CodeArtifact                         | Domain                                              | Resource policy |
| AWS CodeArtifact                         | Repository                                          | Resource policy |
| Amazon CloudWatch Logs                   | Destination                                         | Resource policy |
| Amazon CloudWatch Logs                   | Delivery destination                                | Resource policy |
| Amazon CloudWatch Logs                   | Resource policy                                     | Resource policy |
| Amazon CloudWatch                        | Observability Access Manager sink                   | Resource policy |
| AWS Elemental MediaTailor                | Channel                                             | Resource policy |
| Amazon VPC Lattice                       | Service                                             | Resource policy |
| Amazon VPC Lattice                       | Service network                                     | Resource policy |
| Amazon Managed Service for Prometheus    | Workspace                                           | Resource policy |
| AWS HealthOmics                          | Sequence store                                      | Resource policy |
| Amazon CloudWatch RUM                    | App monitor                                         | Resource policy |
| AWS Signer                               | Signing profile                                     | Resource policy |
| AWS Glue                                 | Data Catalog                                        | Resource policy |
| AWS X-Ray                                | Resource policy                                     | Resource policy |
| AWS CloudTrail                           | Channel                                             | Resource policy |
| AWS CloudTrail                           | Event data store                                    | Resource policy |
| AWS WAF                                  | Rule group                                          | Resource policy |
| AWS WAF Classic (global)                 | Rule group                                          | Resource policy |
| AWS WAF Classic (regional)               | Rule group                                          | Resource policy |
| Amazon S3                                | Access Grants instance                              | Resource policy |
| Amazon S3                                | Multi-Region Access Point                           | Resource policy |
| Amazon S3                                | File system                                         | Resource policy |
| Amazon Redshift Serverless               | Namespace                                           | Resource policy |
| Amazon Redshift Serverless               | Snapshot                                            | Resource policy |
| Amazon Bedrock                           | Knowledge base                                      | Resource policy |
| Amazon Bedrock AgentCore                 | Gateway                                             | Resource policy |
| AWS AppSync                              | GraphQL API                                         | RAM share       |
| AWS App Mesh                             | Mesh                                                | RAM share       |
| AWS Network Firewall                     | Firewall policy                                     | RAM share       |
| AWS Network Firewall                     | Rule group                                          | RAM share       |
| Amazon VPC                               | Transit gateway                                     | RAM share       |
| Amazon VPC                               | Transit gateway multicast domain                    | RAM share       |
| Amazon VPC                               | Managed prefix list                                 | RAM share       |
| Amazon EC2                               | Placement group                                     | RAM share       |
| Amazon VPC IP Address Manager (IPAM)     | Resource discovery                                  | RAM share       |
| Amazon VPC                               | Subnet                                              | RAM share       |
| Amazon VPC                               | Security group                                      | RAM share       |
| AWS Service Catalog AppRegistry          | Application                                         | RAM share       |
| AWS Service Catalog AppRegistry          | Attribute group                                     | RAM share       |
| AWS CodeConnections                      | Connection                                          | RAM share       |
| AWS CodeBuild                            | Report group                                        | RAM share       |
| Amazon SageMaker AI                      | Model card                                          | RAM share       |
| AWS Resource Groups                      | Resource group                                      | RAM share       |
| Amazon Route 53                          | Profile (Route 53 Profiles)                         | RAM share       |
| AWS Cloud Map                            | HTTP namespace                                      | RAM share       |
| Amazon RDS                               | DB cluster                                          | RAM share       |
| Amazon Bedrock                           | Custom model                                        | RAM share       |
| Amazon SageMaker AI                      | Pipeline                                            | RAM share       |
| Amazon SageMaker AI                      | Hub                                                 | RAM share       |
| Amazon SageMaker AI                      | Catalog                                             | RAM share       |
| Amazon SageMaker AI                      | Feature group                                       | RAM share       |
| Amazon EC2                               | Amazon Machine Image (AMI)                          | Attribute share |
| Amazon EC2                               | FPGA image                                          | Attribute share |
| Amazon EBS                               | Snapshot                                            | Attribute share |
| Amazon RDS                               | DB snapshot                                         | Attribute share |
| Amazon RDS                               | DB cluster snapshot                                 | Attribute share |
| Amazon DocumentDB                        | DB cluster snapshot                                 | Attribute share |
| AWS Systems Manager                      | Document                                            | Attribute share |
| Amazon Neptune                           | DB cluster snapshot                                 | Attribute share |
| Amazon Redshift                          | Cluster snapshot                                    | Attribute share |

<Note>
  The Amazon ECR registry, AWS Glue Data Catalog, AWS X-Ray resource policy, and Amazon CloudWatch Logs resource policy are account and region-scoped policies. Plerion surfaces each as its own asset rather than as a policy on an individual resource.
</Note>

***

## What Plerion does not evaluate

* **Access with no AWS-side record of the recipient**, such as IAM access keys or API keys. There is nothing on the AWS side that identifies who holds them.
* **Service Control Policies (SCPs) and Resource Control Policies (RCPs).** Plerion evaluates what a resource grants, not the organization-level guardrails that may further restrict it.

***

## Related pages

* [Resource access grants overview](/guides/platform/resource-access-grants/overview): How Plerion builds and classifies grants.
* [External access](/guides/platform/resource-access-grants/external-access): The grants that reach principals outside your organization.
* [Access review](/guides/platform/resource-access-grants/access-review): Assign grantees, record decisions, and keep an audit history.
