why "power user" privileges for simply send emails with ses via api? This role provides an AWS Directory Service user or group with FULL access to AWS services and resources, only disallow management of IAM users and groups.
@rbuitrago - There's not the exact need for the PowerUser access, you can try a lower privilege.
I gave PowerUser example because in the way amazon ses iam was organized before their changes was simpler to showcase that policy and use it. And the access is not only for sending, but also for managing sns topics.