Products: Managed Backup (Agent), Managed Backup (Web)
Article ID: m0234Last Modified: 03-Oct-2026

Granular User Policies for Wasabi

Create User Policy for Wasabi User Account

In the Wasabi Management Console, create the user policy using one of the policies suggested below.

To associate a policy with the user, perform the following steps:

  1. In the Wasabi Management Console, click Users in the Wasabi menu on the left of the screen. Find the user you want to associate the policy with.
  2. Check whether the user access is configured as follows:
  • Programmatic (create API key)

-OR-

  • Console (Wasabi Management Console access)
  1. Click in the Attach Policy To User area and attach the newly created policy defined for your account. You can enter text to find a specific policy. For details, refer to the Wasabi Documentation.

Multi-bucket policy

This granular policy includes the minimal set of permissions required to use all of the Backup software’s functionality, including backup, restore, retention policy, Object Lock for GFS backups, and backup data deletion.

It is strongly recommended not to use the root user. Create a dedicated user for backups and use the policy below for this user.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket",
        "s3:GetBucketLocation",
        "s3:GetBucketVersioning",
        "s3:ListBucketMultipartUploads",
        "s3:ListBucketVersions",
        "s3:GetBucketObjectLockConfiguration",
        "s3:PutBucketObjectLockConfiguration",
        "s3:AbortMultipartUpload",
        "s3:ListMultipartUploadParts",
        "s3:DeleteObject",
        "s3:DeleteObjectVersion",
        "s3:GetObject",
        "s3:GetObjectVersion",
        "s3:PutObject",
        "s3:PutObjectRetention",
        "s3:ListAllMyBuckets",
        "s3:CreateBucket"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Deny",
      "Action": [
        "s3:BypassGovernanceRetention",
        "s3:DeleteBucket"
      ],
      "Resource": "*"
    }
  ]
}

This user policy allows the following:

  • perform backup
  • list data
  • run restores
  • enable Object Lock for GFS backups
  • create buckets

This policy denies:

  • deletion of data protected by Object Lock/WORM/Immutability
  • deletion of buckets

Single-Bucket policy

This granular policy includes the minimal set of permissions required to use all of the Backup software’s functionality, including backup, restore, retention policy, immutability, and backup data deletion.

Make sure to replace bucket_name with the name of the target bucket.

{
 "Version": "2012-10-17",
 "Statement": [
  {
   "Effect": "Allow",
   "Action": [
    "s3:CreateBucket",
    "s3:GetLifecycleConfiguration",        
    "s3:GetObjectRetention",
    "s3:PutBucketVersioning",
    "s3:PutLifecycleConfiguration",
    "s3:ListBucket",
    "s3:GetBucketLocation",
    "s3:GetBucketVersioning",
    "s3:ListBucketMultipartUploads",
    "s3:ListBucketVersions",
    "s3:GetBucketObjectLockConfiguration",
    "s3:PutBucketObjectLockConfiguration"
   ],
   "Resource": "arn:aws:s3:::bucket_name"
  },
  {
   "Effect": "Allow",
   "Action": [
    "s3:AbortMultipartUpload",
    "s3:ListMultipartUploadParts",
    "s3:DeleteObject",
    "s3:DeleteObjectVersion",
    "s3:GetObject",
    "s3:GetObjectVersion",
    "s3:PutObject",
    "s3:PutObjectRetention"
   ],
   "Resource": "arn:aws:s3:::bucket_name/*"
  },
  {
   "Effect": "Allow",
   "Action": "s3:ListAllMyBuckets",
   "Resource": "*"
  }
 ]
}
https://git.cloudberrylab.com/egor.m/doc-help-mbs.git
Production