Role Overview

Last Updated At: 2025-10-14 13:39:29

What is a Role?

A role can be considered as a virtual account within Converge Cloud. Roles can also be granted policies, possessing permissions to allow or deny actions within Converge Cloud. Roles can be assumed by any Converge Cloud account and are not exclusively associated with a bind account. Roles do not have associated persistent credentials (passwords or access tokens). The root account only needs to use persistent credentials when applying for a role. When a user takes on a role, temporary credentials are dynamically created and provided to the user for accessing the corresponding resources through temporary tokens to sign API calls to access the user's cloud resources.

Use Scenes for Roles

Cloud Account Role

Cloud account roles are used to enable resource access across tenants. For example, in certain delegated operations scenes, Tenant A can use roles to allow Tenant B to access specific resources within Tenant A.