Under the corporate account CompanyExample (ownerUin 12345678), there is a sub-account Developer. This sub-account requires permissions to view cloud disk information, create cloud disks, and use cloud disks in the CVM Console under the CVM service of the corporate account CompanyExample.
Scenario A:
The corporate account CompanyExample directly grants the preset policy QcloudCBSFullAccess to the sub-account Developer. For the method of authorization, please see Authorization Management.
Scenario B:
1. Create a policy through policy syntax.
{"version": "2.0","statement": [{"action": ["cvm:CreateCbsStorages","cvm:AttachCbsStorages","cvm:DetachCbsStorages","cvm:ModifyCbsStorageAttributes","cvm:DescribeCbsStorages","cvm:DescribeInstancesCbsNum","cvm:RenewCbsStorage","cvm:ResizeCbsStorage"],"resource": "*","effect": "allow"}]}
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.
Note
If the sub-account is not permitted to modify cloud disk attributes, remove cvm:ModifyCbsStorageAttributes from the above policy syntax.