Skip to content

Least-Privilege Permissions Reference

Every permission the AccuKnox CSPM scanner requests is read-only. It reads how your resources are configured to flag misconfigurations and build your asset inventory. It never changes anything, and never reads object contents, database rows, or secret payloads.

Pick your cloud to see every permission, grouped by service, with the reason for each on hover:

Cloud Permissions Full list
AWS 403 AWS Permissions Reference
Azure 209 Azure Permissions Reference
GCP 901 GCP Permissions Reference

Denying a permission does not break the scan. It only creates a blind spot for that service: missing assets, or skipped findings.