Permissions for @turbot/aws-cloudtrail

Taking a look at permissions and associated grant levels for each permission for CloudTrail:

PermissionGrant LevelHelp
cloudtrail:AddTagsOperator
cloudtrail:CreateTrailAdmin
cloudtrail:DeleteTrailAdmin
cloudtrail:DescribeTrailsMetadata
cloudtrail:GetEventSelectorsMetadata
cloudtrail:GetInsightSelectorsMetadata
cloudtrail:GetTrailMetadata
cloudtrail:GetTrailStatusMetadata
cloudtrail:ListPublicKeysMetadata
cloudtrail:ListTagsMetadata
cloudtrail:ListTrailsMetadata
cloudtrail:LookupEventsMetadataCloudTrail events do not contain any data just information about the API call.
cloudtrail:PutEventSelectorsAdmin
cloudtrail:PutInsightSelectorsAdmin
cloudtrail:RemoveTagsOperator
cloudtrail:StartLoggingOperator
cloudtrail:StopLoggingOperator
cloudtrail:UpdateTrailAdmin
kms:ListAliasesMetadataFor console access per http://docs.aws.amazon.com/awscloudtrail/latest/userguide/grant-custom-permissions-for-cloudtrail-users.html
s3:GetBucketLocationMetadataFor console access per http://docs.aws.amazon.com/awscloudtrail/latest/userguide/grant-custom-permissions-for-cloudtrail-users.html
s3:ListAllMyBucketsMetadataFor console access per http://docs.aws.amazon.com/awscloudtrail/latest/userguide/grant-custom-permissions-for-cloudtrail-users.html