Under the corporate account CompanyExample (ownerUin 12345678), there is a sub-account named Developer. This sub-account requires the permission to view all VPC resources and only to perform adding, deleting, modifying, and querying operations on VPN of the corporate account CompanyExample.
1. Create a policy through policy syntax.
{"version": "2.0","statement": [{"action": ["vpc:Describe*","vpc:Inquiry*","vpc:Get*"],"resource": "*","effect": "allow"},{"action": ["vpc:Vpn","vpc:UserGw"],"resource": "*","effect": "allow"}]}
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.