Under the corporate account CompanyExample (ownerUin is 12345678), there is a sub-account named Developer. This sub-account requires the permission to query CVM instances of the CompanyExample's CVM service, but does not have the permissions of creation, deletion, or powering-on/off.
Scenario A:
The corporate account CompanyExample directly grants the preset policy QcloudCVMInnerReadOnlyAccess to the sub-account Developer. For the method of authorization, please see Authorization Management.
Scenario B:
1. Create a policy through policy syntax.
{"version": "2.0","statement":[{"effect": "allow","action": ["cvm:Describe*","cvm:Inquiry*"],"resource": "*"}]}
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.