diff --git a/terraform/modules/container/README.md b/terraform/modules/container/README.md
index 2942f06..f85e9f7 100644
--- a/terraform/modules/container/README.md
+++ b/terraform/modules/container/README.md
@@ -155,6 +155,6 @@ No modules.
|------|-------------|
| [execution\_role\_arn](#output\_execution\_role\_arn) | ARN of the execution role generated for this container. It pulls the image, writes logs and reads secrets, scoped to this container's project. |
| [execution\_role\_name](#output\_execution\_role\_name) | IAM role name of the execution role generated for this container. |
-| [task\_role\_arn](#output\_task\_role\_arn) | ARN of the task role that this container uses. Good for setting up permissions like s3 access |
+| [task\_role\_arn](#output\_task\_role\_arn) | ARN of the task role that this container uses. This is the role application code runs as, and the place project-specific AWS permissions go. See [Container Permissions](https://github.com/hackforla/incubator/wiki/Container-Permissions) on the incubator wiki for what it already grants and how to add to it. |
| [task\_role\_name](#output\_task\_role\_name) | IAM role name of the task role that this container uses. |
\ No newline at end of file
diff --git a/terraform/modules/container/outputs.tf b/terraform/modules/container/outputs.tf
index 4d4d485..64bc64c 100644
--- a/terraform/modules/container/outputs.tf
+++ b/terraform/modules/container/outputs.tf
@@ -1,5 +1,5 @@
output "task_role_arn" {
- description = "ARN of the task role that this container uses. Good for setting up permissions like s3 access"
+ description = "ARN of the task role that this container uses. This is the role application code runs as, and the place project-specific AWS permissions go. See [Container Permissions](https://github.com/hackforla/incubator/wiki/Container-Permissions) on the incubator wiki for what it already grants and how to add to it."
value = aws_iam_role.instance.arn
}