Guide / Permissions
Permissions
neboto needs read permissions for the services you actually browse. The
quickest correct answer is the AWS-managed ReadOnlyAccess policy.
For accounts that need a narrower, auditable grant, the complete per-service
action list is maintained in
PERMISSIONS.md,
updated in the same commit as any change that adds an API call. A guard in
the project’s CI checks every SDK operation and every listed IAM action
against a read-only vocabulary, so a write call cannot slip in unnoticed.
Calls worth a second look
PERMISSIONS.md calls out the few reads that deserve a conscious decision:
- Opt-in reveals:
secretsmanager:GetSecretValueandssm:GetParameterwith decryption are only issued when you press x or Y on a secret. Values are never cached, logged, or written anywhere; they go to the screen or the clipboard and nowhere else. Leave these actions out of the policy and the reveal simply fails. - Calls that cost money:
ce:GetCostAndUsagebills about $0.01 per request (cached six hours);dynamodb:ScanandQueryconsume read capacity; CloudWatchGetMetricDatabills per metric, which is why the dashboard view caps its series. - Data-plane calls that can start things: Bedrock AgentCore’s
GetAgentCardreaches the running agent and can cold-start it, so it is gated behind x rather than fired on view. - S3 configuration reads whose IAM action names do not match the
s3:GetBucket*wildcard. sts:AssumeRolebehind the member-account switch.
Why read-only
This is a design constraint, not a missing feature.
- The Organizations member-account switch pins every assumed session to a
ReadOnlyAccesssession policy. Write actions would either fail silently cross-account or force that guarantee to be weakened. - A permissions document that describes a purely read-only footprint is a trust asset. Security teams can approve neboto precisely because it cannot mutate. One gated write action changes that conversation permanently.
Where a mutation is genuinely what you want, C copies the ready-to-run AWS CLI command for the selected resource, with the region and ids filled in. You never reconstruct an ARN by hand, and neboto never holds the ability to run it.
Reporting a security issue
Use GitHub’s private vulnerability reporting on the repository, or email
stojan@neboto.dev. Details are in
SECURITY.md.