Principal subject matcher; supports | for OR.
Restrict by action type or include both.
IAM verb matcher; supports | for OR.
Inactive
Resource or family matcher.
Inactive
Matches normalized permission text.
Location clause matcher. "tenancy" or name of compartment.
Path where the policy is defined.
Raw statement text contains match.
Policy name contains match.
Final effective evaluation path.
Condition clause contains match.
Filter by parser validity state.
Advanced: filter helper actions
Resource → Family + all-resources
Builds
resource|family|all-resources in Resource filter.Family → members + all-resources
Builds
family|resource1|resource2|...|all-resources in Resource filter.Permission Lookup
Add individual
PERMISSION elements to the Permission filter using the lookup fly-in. Searching for permissions clears the Resource filter because they are mutually exclusive and cannot exist together in the same policy statement.Advanced: tag-based policy filters
Tag Condition
Use these with regular filters like Verb, Resource, Permission, and Effective Path.
Namespace / Key / Value
When several tag fields are entered, one parsed tag condition must match all of them.
After filtering, click a statement and check Statement Details for Tag-based Details and context warnings.
Advanced: raw JSON payload override
| Compartment / Policy | Effective Path | Statement | Conditions | Verb + Resource / Permission |
|---|