Policy

Last Updated At: 2025-10-21 09:10:00

A policy is a syntax rule used to define and describe one or more permissions. Cloud policies include preset policies and custom policies. CAM provides various methods from different perspectives for creating and managing policies. If you need to add permissions to CAM users or groups, you can directly associate preset policies or create custom policies and then associate them with CAM users or groups. Each policy can contain multiple permissions, and you can attach multiple policies to a CAM user or group.

Preset Policy

Preset policies are created and managed by the cloud. They are collections of common permissions frequently used by users, such as super administrators and full read and write permissions for resources. These policies apply to a broad range of operation objects with coarse-grained operations. As policies preset by the system, they cannot be edited by users.

Custom Policy

Custom policies are created by users to provide a more specific description of resource management permissions. These policies allow for fine-grained permission division and offer the flexibility to meet user requirements for differentiated permission management. For example, you can associate a policy with a specific database administrator to grant it the authority to manage cloud database instances but not CVM instances.