Under the corporate account CompanyExample (with ownerUin 12345678), there is a sub-account named Developer. This sub-account requires operation permissions for a specific VPC (with ID vpc-id1) under the VPC service of the corporate account CompanyExample, as well as the network resources under this VPC (such as subnets, routing tables, and so on, excluding CVM, databases, and so on).
1. Create a policy through policy syntax.
{"version": "2.0","statement": [{"action": "vpc:*","resource": "*","effect": "allow","condition": {"string_equal_if_exist": {"vpc:vpc": ["vpc-id1"],"vpc:accepter_vpc": ["vpc-id1"],"vpc:requester_vpc": ["vpc-id1"]}}}]}
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.