It should be the account admin with IAM credentials. Example policy for creating and managing groups (IAM policy examples for Amazon QuickSight - Amazon QuickSight ) : Attaching this policy to the IAM user who is an Admin logging into Quick Sight will be able to for eg : create a new group .