# PolicyStatement

A permission statement within a policy document.

**Sid** string

Optional identifier for the statement

**Effect** string required

Whether this statement allows or denies the specified actions

**Possible values:** [`Allow`, `Deny`]

**Action** string[] required

S3 actions to allow or deny. Common actions: `s3:GetObject`, `s3:PutObject`, `s3:DeleteObject`, `s3:ListBucket`, `s3:*`. See [supported actions](/content/docs/iam/policies/supported-actions/index.html).

**Resource** string[] required

S3 resource ARNs. Use `arn:aws:s3:::bucket` for bucket-level and `arn:aws:s3:::bucket/prefix/*` for prefix-scoped access.

**Condition** object

Optional conditions (IP, time-based). See [condition examples](/content/docs/iam/policies/examples/ip-restrictions/index.html).

PolicyStatement

```json
{

"Sid": "string",

"Effect": "Allow",

"Action": [

"string"

],

"Resource": [

"string"

],

"Condition": {}

}
```
