Under the corporate account CompanyExample (ownerUin 12345678), there is a sub-account named Developer. This sub-account requires read/write permissions for the VPC service and its related resources of the corporate account CompanyExample, but it is not permitted to perform operations related to the routing table.
1. Create a policy through policy syntax.
{"version": "2.0","statement": [{"action": ["vpc:*"],"resource": "*","effect": "allow"},{"action": ["vpc:AssociateRouteTable","vpc:CreateRoute","vpc:CreateRouteTable","vpc:DeleteRoute","vpc:DeleteRouteTable","vpc:ModifyRouteTableAttribute"],"resource": "*","effect": "deny"}]}
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.