Permissions for @turbot/aws-workspaces

Taking a look at permissions and associated grant levels for each permission for WorkSpaces:

PermissionGrant LevelHelp
iam:GetRoleMetadata
iam:PassRoleAdminAdmins can allow workspace to use workspaces_DefaultRole role to create and delete network interface and required permissions.
workspaces:AssociateIpGroupsAdminAdmins can associate the specified IP access control group with the specified directory.
workspaces:AuthorizeIpRulesAdminAdmins can add one or more rules to the specified IP access control group.
workspaces:CopyWorkspaceImageOperator
workspaces:CreateIpGroupAdminAdmins can create an IP access control group.
workspaces:CreateRegistrationAdmin
workspaces:CreateTagsOperatorOperators can manage existing WorkSpace instances.
workspaces:CreateWorkspacesAdminAdmins can manage create/terminate WorkSpace Instances.
workspaces:DeleteIpGroupAdmin
workspaces:DeleteTagsOperatorOperators can manage existing WorkSpace instances.
workspaces:DeleteWorkspaceImageAdmin
workspaces:DeregisterWorkspaceDirectoryAdmin
workspaces:DescribeAccountMetadataRetrieves a list that describes the configuration of bring your own license (BYOL) for the specified account.
workspaces:DescribeAccountModificationsMetadataRetrieves a list that describes modifications to the configuration of bring your own license (BYOL) for the specified account.
workspaces:DescribeClientPropertiesMetadataDescribe client properties about the specified resources.
workspaces:DescribeIpGroupsMetadata
workspaces:DescribeTagsMetadata
workspaces:DescribeWorkspaceBundlesMetadata
workspaces:DescribeWorkspaceDirectoriesMetadata
workspaces:DescribeWorkspaceImagesMetadataRetrieves a list that describes one or more specified images.
workspaces:DescribeWorkspaceSnapshotsMetadata
workspaces:DescribeWorkspacesMetadata
workspaces:DescribeWorkspacesConnectionStatusMetadata
workspaces:DisassociateIpGroupsAdmin
workspaces:ImportWorkspaceImageAdminImport a licensed EC2 image to into Amazon WorkSpaces.
workspaces:ListAvailableManagementCidrRangesMetadataList available CIDR ranges for a CIDR range constraint.
workspaces:ModifyAccountAdminModify the configuration of bring your own license (BYOL) for the specified account.
workspaces:ModifyClientPropertiesAdminModify the client properties of a specified resource.
workspaces:ModifySelfservicePermissionsAdmin
workspaces:ModifyWorkspaceAccessPropertiesAdmin
workspaces:ModifyWorkspaceCreationPropertiesAdmin
workspaces:ModifyWorkspacePropertiesOperatorOperators can manage existing WorkSpace instances.
workspaces:ModifyWorkspaceStateOperatorOperators can change the state of workSpace to ADMIN_MAINTENANCE inorder to perform maintenance.
workspaces:RebootWorkspacesOperatorOperators can manage existing WorkSpace instances.
workspaces:RebuildWorkspacesOperatorOperators can manage existing WorkSpace instances.
workspaces:RegisterWorkspaceDirectoryAdmin
workspaces:RestoreWorkspaceAdmin
workspaces:RevokeIpRulesAdminAdmins can remove one or more rules from the specified IP access control group.
workspaces:StartWorkspacesOperatorOperators can manage existing WorkSpace instances.
workspaces:StopWorkspacesOperatorOperators can manage existing WorkSpace instances.
workspaces:TerminateWorkspacesAdminAdmins can manage create/terminate WorkSpace Instances.
workspaces:UpdateRulesOfIpGroupAdmin