Revised Cost & Compliance Role Permissions
Stax has released a new version of the Cost & Compliance module's service and billing roles, version 30. In keeping with our principle of least-privilege, Stax has revised the permissions this role requires.
Specifically, Stax no longer requires access to AWS Support APIs to complete compliance discovery tasks.
If your AWS accounts are Stax-managed, then you don't need to take any action. Stax will automatically update this role in the coming days.
If you're subscribed only to the Stax Cost & Compliance module, you will need to apply the update yourself.
As always, Stax recommends that you regularly review your IAM permissions. It is important to confirm that they align with the principle of least-privilege, and with the AWS Well-Architected Framework. For any questions around this change, or if you need assistance deploying the updated role, please raise a support case.