Help & Documentation>Cloud Access Management>Business Use Cases>CVM>Authorizing Sub-account Full Access to CVMs Except Payment

Authorizing Sub-account Full Access to CVMs Except Payment

Last updated: 2024-09-30 16:59:47
Under the corporate account CompanyExample (with ownerUin 12345678), there is a sub-account named Developer. This sub-account requires full management permissions (including creation, management, and all other operations) for the CVM services of the corporate account CompanyExample, but payment permissions are not included. That is, it can place orders but cannot make payments.

Scenario A:

The corporate account CompanyExample directly grants the preset policy QcloudCVMFullAccess to the sub-account Developer. For the granting method, please see Authorization Management.

Scenario B:

1. Create a policy through policy syntax.
{
"version": "2.0",
"statement":[
{
"effect": "allow",
"action": "cvm:*",
"resource": "*"
}
]
}
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.