Help & Documentation>Cloud Access Management>Business Use Cases>Others>Granting Management or Read-Only Permissions for Specified Product

Granting Management or Read-Only Permissions for Specified Product

Last updated: 2024-02-01 21:25:33
To streamline the configuration of user permissions, Tencent Cloud products provide default permission granting policies when integrating with Cloud Access Management (CAM). These policies can be directly associated with CAM sub-accounts or user groups to control access to corresponding product services. These policies fall under the category of preset CAM policies, with each type of product service typically offering at least management and read-only policies.
1. Navigate to the Access Management > Policies console. Enter the product name (such as Cloud Server) in the search box to view the preset policy list for the corresponding product.

Among them, QcloudCVMFullAccess is the management policy, and QcloudCVMInnerReadOnlyAccess is the read-only policy.
Note
The management policies of some services do not include payment permissions. You can associate a default payment management policy (such as QcloudCVMFullAccess) with the CAM sub-user/user group you want to authorize.
2. Grant the aforementioned policies to the CAM sub-account/user group. For the method of authorization, please see Authorization Management.
If you need to grant a sub-user full management permissions for a Tencent Cloud account, you can use the preset policy AdministratorAccess. AdministratorAccess: This policy allows you to manage all users within the account, their permissions, financial-related information, and cloud service assets.
If you need to grant read-only access to a Tencent Cloud account to a sub-user, you can use the preset policy ReadOnlyAccess. ReadOnlyAccess: This policy allows you to have read-only access to all cloud service assets within the account that support interface-level or resource-level authentication.