CAM provides the following features:
Managing access permissions
You can create a sub-account and grant it management permissions for the resources under the root account, without sharing the root account's identity credentials.
Granular permission management
You can assign different access permissions to different resources for different personnel. For instance, you can allow certain sub-accounts to have read access to a specific COS bucket, while other sub-accounts can have write access to a specific COS storage object, etc. Here, resources, access permissions, and users can all be bundled together. For example, you can create a bucket and set a group of sub-accounts with read permissions, a group with write permissions, and a group with management permissions on this bucket. Once set, you can add the users to be authorized in bulk to the corresponding sub-accounts and assign the corresponding access permissions to the respective sub-accounts.
Federated Identity
Users who get passwords through CAM using your existing identity verification system (for example, your enterprise network or through an Internet identity provider) can obtain temporary access permissions to your Tencent Cloud account.
Data integrity
CAM is now available in Tencent Cloud in multiple regions, which allows you to synchronize cross-region data simply through replicating policy data. Although the modified CAM policies will be submitted immediately, the cross-region policy synchronization can result in delayed effects. CAM utilizes cache to improve performance, which may increase the latency in some cases as updates do not take effect until the cache expires.