A user cannot do something they should
You granted the access, the person still gets a permission error. Work through these in order. The first two explain most cases.
1. The change has not reached them yet
Permissions are read at sign-in and refreshed periodically, so a change takes up to about five minutes to apply.
Ask them to sign out and back in. If it works after that, this was it.
2. The permission is on the wrong target
A permission is only valid where it was granted. Someone with vm:power on VDC A cannot restart a machine in VDC B, even though the permission appears in their list.
Open the Permissions tab on the person and look at the scope next to the permission, not just at its presence. If the target is wrong, assign the group again on the right one.
Granting at customer level covers every VDC of that customer at once, and is usually what you want for someone who works across the whole environment.
3. They have the permission, but not the one being checked
Reading is usually covered by a broad <section>:view key, but sensitive actions have their own. Someone with vm:view still cannot open the console without vm:console:view, and cannot see the audit trail without iam:audit:view.
Check the permission catalog for the exact key the action needs.
4. The grant expired
Direct grants always have an expiry date. Look at the Grants tab: an expired grant stays in the list, marked Expired, so it is easy to mistake for active access.
An expired grant cannot be renewed, so create a new one. If the need turned out to be permanent, move the permission into a group instead.
5. The account is blocked or pending
A blocked user is refused at sign-in regardless of permissions. A pending user never accepted the invite. Both show on the Users tab.
Actions the platform refuses
These are rejected on purpose, and the message on screen explains which one you hit.
| What you tried | Why it is refused |
|---|---|
| Creating a grant with an expiry date in the past | A direct grant has to expire in the future |
| Renewing to a date that is not later than the current one | A renewal has to extend. To shorten access, revoke and create a new grant |
| Renewing a grant that already expired | Expired grants cannot be revived. Create a new one |
| Revoking a grant that is already revoked | It is already inactive, there is nothing to do |
| Assigning without choosing a customer or VDC | Customer and VDC scopes need a target |
| Granting a permission at a level it does not allow | Each key lists which scopes it accepts, see the permission catalog |
| Editing a built-in group | System groups are read only. Duplicate one and edit the copy |
| Resending an invite to someone who already accepted | Resending only works while the invite is pending |
| Disabling an account that is pending or already disabled | Only an active account can be disabled |