Permissions for @turbot/aws-config

Taking a look at permissions and associated grant levels for each permission for Config:

PermissionGrant LevelHelp
config:BatchGetAggregateResourceConfigMetadata
config:BatchGetResourceConfigMetadata
config:DeleteAggregationAuthorizationAdminIt deletes the authorization granted to the specified configuration aggregator account in a specified region. It is a cross-account permission.
config:DeleteConfigRuleAdminAdmin can delete the specified AWS Config rule and all of its evaluation results.
config:DeleteConfigurationAggregatorAdmin
config:DeleteConfigurationRecorderAdminAdmins manage configuration recorder settings.
config:DeleteConformancePackAdmin
config:DeleteDeliveryChannelAdminAdmins manage delivery channel settings.
config:DeleteEvaluationResultsAdmin
config:DeleteOrganizationConfigRuleAdmin
config:DeleteOrganizationConformancePackAdmin
config:DeletePendingAggregationRequestAdmin
config:DeleteRemediationConfigurationAdmin
config:DeleteRemediationExceptionsAdmin
config:DeleteResourceConfigAdmin
config:DeleteRetentionConfigurationAdmin
config:DeliverConfigSnapshotOperatorOperators can schedule config snapshot deliveries to S3.
config:DescribeAggregateComplianceByConfigRulesMetadata
config:DescribeAggregationAuthorizationsMetadata
config:DescribeComplianceByConfigRuleMetadataMetadata about config rules and resources; allow Metadata to Describe rules.
config:DescribeComplianceByResourceMetadataMetadata about config rules and resources; allow Metadata to Describe rules.
config:DescribeConfigRuleEvaluationStatusMetadataMetadata about config rules and resources; allow Metadata to Describe rules.
config:DescribeConfigRulesMetadataMetadata about config rules and resources; allow Metadata to Describe rules.
config:DescribeConfigurationAggregatorSourcesStatusMetadata
config:DescribeConfigurationAggregatorsMetadata
config:DescribeConfigurationRecorderStatusMetadataMetadata about config settings; allow Metadata to Describe these settings.
config:DescribeConfigurationRecordersMetadataMetadata about config settings; allow Metadata to Describe these settings.
config:DescribeConformancePackComplianceMetadata
config:DescribeConformancePackStatusMetadata
config:DescribeConformancePacksMetadata
config:DescribeDeliveryChannelStatusMetadataMetadata about config settings; allow Metadata to Describe these settings.
config:DescribeDeliveryChannelsMetadataMetadata about config settings; allow Metadata to Describe these settings.
config:DescribeOrganizationConfigRuleStatusesMetadata
config:DescribeOrganizationConfigRulesMetadata
config:DescribeOrganizationConformancePackStatusesMetadata
config:DescribeOrganizationConformancePacksMetadata
config:DescribePendingAggregationRequestsMetadata
config:DescribeRemediationConfigurationsMetadata
config:DescribeRemediationExceptionsMetadata
config:DescribeRemediationExecutionStatusMetadata
config:DescribeRetentionConfigurationsMetadata
config:GetAggregateComplianceDetailsByConfigRuleMetadata
config:GetAggregateConfigRuleComplianceSummaryMetadata
config:GetAggregateDiscoveredResourceCountsMetadata
config:GetAggregateResourceConfigMetadata
config:GetComplianceDetailsByConfigRuleMetadataMetadata about config rules and resources; allow Metadata to Get rules.
config:GetComplianceDetailsByResourceMetadataMetadata about config rules and resources; allow Metadata to Get rules.
config:GetComplianceSummaryByConfigRuleMetadataMetadata about config rules and resources; allow Metadata to Get rules.
config:GetComplianceSummaryByResourceTypeMetadataMetadata about config rules and resources; allow Metadata to Get rules.
config:GetConformancePackComplianceDetailsMetadata
config:GetConformancePackComplianceSummaryMetadata
config:GetDiscoveredResourceCountsMetadataMetadata about the number of each resource type and the total number of resources that AWS Config is recording in this region for your AWS account.
config:GetOrganizationConfigRuleDetailedStatusMetadata
config:GetOrganizationConformancePackDetailedStatusMetadata
config:GetResourceConfigHistoryMetadataAWS config is only metadata about resources; allow Metadata to Get data.
config:GetResourcesMetadataAWS config is only metadata about resources; allow Metadata to Get data.
config:GetTagKeysMetadataAWS config is only metadata about resources; allow Metadata to Get data.
config:ListAggregateDiscoveredResourcesMetadata
config:ListDiscoveredResourcesMetadataAWS config is only metadata about resources; allow Metadata to Get data.
config:ListTagsForResourceMetadata
config:PutAggregationAuthorizationAdminIt authorizes the aggregator account and region to collect data from the source account and region.
config:PutConfigRuleAdminAdmin can add or update an AWS Config rule for evaluating whether your AWS resources comply with desired configurations.
config:PutConfigurationAggregatorAdmin
config:PutConfigurationRecorderAdminAdmins manage config recorder settings.
config:PutConformancePackAdmin
config:PutDeliveryChannelAdminAdmins manage delivery channel settings.
config:PutEvaluationsOperator
config:PutOrganizationConfigRuleAdmin
config:PutOrganizationConformancePackAdmin
config:PutRemediationConfigurationsAdmin
config:PutRemediationExceptionsAdmin
config:PutResourceConfigAdmin
config:PutRetentionConfigurationAdminCreates and updates the retention configuration with details about retention period that AWS Config stores your historical information.
config:SelectResourceConfigMetadata
config:StartConfigRulesEvaluationOperatorOperator can run an on-demand evaluation for the specified Config rules against the last known configuration state of the resources.
config:StartConfigurationRecorderOperatorOperators can start config recorders across regions.
config:StartRemediationExecutionAdmin
config:StopConfigurationRecorderOperatorOperators can stop config recorders across regions.
config:TagResourceOperator
config:UntagResourceOperator
iam:ListRolesMetadata
iam:PassRoleAdmin"Admins need 'iam:PassRole' to attach the applicable service role for Config settings."