Required IAM Policy
To use Oracle Cloud Infrastructure, you must be granted the required type of access in a policy (IAM) written by an administrator.
Examples:
- Allow users in the group
Admins
to create, update, and delete all Managed Access resources in the tenancy:Allow group Admins to manage lockbox-family in tenancy
- Allow users in the group
SecurityAdmins
to manage approval templates in the tenancy:Allow group SecurityAdmins to manage approval-templates in tenancy
- Allow users in the group
SecurityAdmins
to manage approval templates in tenancy except the specified compartment:Allow group SecurityAdmins to manage approval-templates in tenancy target.compartment.id != 'ocid1.compartment.oc1..aaaaaaaaexampleocid'
For all policies, see Managed Access Policies.
approval-template
Verbs | Permissions |
---|---|
inspect |
|
read |
+ inspect
|
use |
+ read
|
manage |
+ use
|