Under the corporate account CompanyExample (with ownerUin as 12345678), there is a sub-account named Developer. This sub-account requires operation permissions for specific CVMs under the corporate account CompanyExample. These CVMs are all tagged game&webpage.
1. Create a policy through policy syntax.
{"version": "2.0","statement": [{"effect": "allow","action": ["cvm:*","vpc:DescribeVpcEx","vpc:DescribeNetworkInterfaces"],"resource": "*","condition": {"for_any_value:string_equal": {"qcs:resource_tag": ["game&webpage"]}}}]}
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.