This screenshot is from the AWS KMS Create key wizard at Step 3 (optional): Define key administrative permissions. It shows the Key administrators list, where the IAM role OracleDBKMS_vmc_esr4tv5j5o is selected to administer the key. The checkbox under Key deletion is enabled, allowing key administrators to delete the key. The Next button will continue to defining key usage permissions and the key policy.