If your company requires an additional layer of security, you can create your own restricted permissions policy. At minimum, imgix requires the read-only permissions `ListBucket`, `GetBucketLocation` and `GetObject` to serve your assets. With a restricted policy, you can also define which specific S3 bucket(s) imgix can have access to.
Please visit our documentation, [docs.imgix.com/setup/creating-sources/amazon-s3#security](http://docs.imgix.com/setup/creating-sources/amazon-s3#security), for more information regarding this advanced flow.
In this tutorial, we’ll be keeping it simple and attaching a pre-existing, read-only Amazon policy template.