An account on the CryptoHub with administrator permissions to deploy new services.
An AWS IAM role assigned the AWSKeyManagementServicePowerUser AWS-managed policy, along with the customer-managed policy below, which grants additional permissions needed to test XKS end-to-end: