Under the corporate account CompanyExample (with ownerUin as 12345678), there is a sub-account named cdb. This sub-account has been granted full operation permissions (*) for all CDB instances within a specific region (gz). Specifically, this sub-account has the permission to execute any operation on these CDB instances.
1. Create a policy through policy syntax.
{"version": "2.0""statement": [{"action": "cdb:*","resource": "qcs::cdb:gz::*","effect": "allow"}]}
action: Indicates the permitted operation.
cdb:* signifies that all CDB operations are allowed.effect: Indicates whether the permission described in the statement is allowed or denied.
allow signifies that the permission is allowed.resource: Indicates the scope of resources applicable to this statement.
qcs::cdb:gz::* signifies that the sub-account is granted full operation permissions for all CDB instances within a specific region (gz). * represents a wildcard, indicating permissions for all instances.2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.