How to configure permissions
Access is given by assigning a group to a person, on a target. This page covers the three things you will do in practice: assigning a group, building your own, and the exception case of granting a single permission.
Prerequisites
iam:group:assignto assign groups,iam:group:manageto create them,iam:grant:createfor direct grants.- The vocabulary in What is IAM.
Assign a group to someone
- Open IAM and go to the Assigned groups tab.
- Click Assign group.
- User: pick the person.
- Group: pick the group. Only the groups you are allowed to hand out appear here.
- Target: pick the customer or VDC the access applies to. The scope itself comes from the group, so there is nothing to choose there. A VDC group asks for a VDC, a customer group asks for a customer.
- Governance: write the reason. It is required and recorded in the audit log.
- Check the summary and confirm.
The access takes effect on the person's next token refresh, within about five minutes.
Group access does not expire. It lasts until someone removes the assignment.
Create your own group
When neither default group fits, build one:
- Go to the Groups tab and click Create group.
- Give it a name and a description that says what the group is for.
- Choose the scope type it can be assigned at. This is the decision that matters most: a VDC group can only ever be assigned to VDCs, and a customer group only to customers. It cannot be changed by assignment later.
- Pick its permissions from the catalog. Filter by domain to find them.
- Save, then assign it exactly like a default group.
Built-in groups are read only. To start from one, duplicate it and edit the copy.
Grant a single permission
For a one-off exception, skip groups entirely:
- Go to the Grants tab and click Create grant.
- Pick the person and the permission.
- Choose the scope and, when it needs one, the target. A permission is not tied to a single level the way a group is, so here you do pick the scope.
- Set an expiry date. It is mandatory and has to be in the future.
- Write the reason and confirm.
See How to give temporary access for renewing and revoking.
Use this sparingly. If several people need the same exception, create a group instead. Grants scattered across users are what makes access impossible to review later.
Notes
- You cannot grant what you do not hold. The lists are filtered to your own access, on the target you picked.
- Permissions only add up. To take access away, remove the assignment or revoke the grant. There is no deny rule.
- Use the Permissions tab on a person to see everything they hold and where each item came from.