privilege
The scope of the temporary access credential that S3 Access Grants vends to the grantee or client application.
Default– The scope of the returned temporary access token is the scope of the grant that is closest to the target scope.Minimal– The scope of the returned temporary access token is the same as the requested target scope as long as the requested scope is the same as or a subset of the grant scope.