The `data` role is able to set up read-only/read-write access to external AWS S3 buckets for IDBroker and Datalake Admin role. However, an additional step is required for DWX -- the same policies need to be assigned to the `NodeInstanceRole` within the DW cluster. See the bottom of the following best practices document: https://community.cloudera.com/t5/Community-Articles/External-AWS-Bucket-Access-in-CDP-Public-Cloud/ta-p/302074