Permissions for @turbot/aws-shield

Taking a look at permissions and associated grant levels for each permission for Shield:

PermissionGrant LevelHelp
iam:GetRoleMetadata
iam:ListAttachedRolePoliciesMetadata
iam:PassRoleAdmin
s3:GetBucketPolicyMetadata
shield:AssociateDRTLogBucketAdmin"Admins can authorize the DDoS Response team to access the specified Amazon S3 bucket containing user's flow logs."
shield:AssociateDRTRoleAdmin"Admins can authorize the DDoS Response team using the specified role to access user's AWS account to assist with DDoS attack mitigation during potential attacks."
shield:CreateProtectionAdmin
shield:CreateSubscriptionAdmin
shield:DeleteProtectionAdmin
shield:DeleteSubscriptionAdmin
shield:DescribeAttackMetadata
shield:DescribeDRTAccessMetadata
shield:DescribeEmergencyContactSettingsMetadata
shield:DescribeProtectionMetadata
shield:DescribeSubscriptionMetadata
shield:DisassociateDRTLogBucketAdmin
shield:DisassociateDRTRoleAdmin
shield:GetSubscriptionStateMetadata
shield:ListAttacksMetadata
shield:ListProtectionsMetadata
shield:UpdateEmergencyContactSettingsAdminAdmins can update the details of the list of email addresses that the DRT can use to contact you during a suspected attack.
shield:UpdateSubscriptionAdmin