Sub-user Permission Settings

Last Updated At: 2025-10-21 09:10:00

Overview

This documentation describes how to authorize and revoke policies associated with sub-users. Sub-users will manage resources under the root account within the granted permissions.

Directions

Authorize Association of Policies for Sub-users

Direct Association

You can directly associate policies with users to obtain the permissions included in the policies.

  1. Log in to the Cloud Access Management Console, select User Management > User to enter the User Management page.
  2. On the User Management page, click on the user to enter the user details page.
  3. Click on Associated Policies to view the policies already associated.
  4. Click on Associate Policy, select policies from the pop-up policy list.
  5. Click OK to complete the direct association of policies for sub-users.

Associated with Groups

You can add users to user groups, and users will automatically obtain the permissions associated with the user group. The policies obtained through this method are associated with groups. To revoke policies associated with groups, remove users from the respective user groups.

  1. Log in to the Cloud Access Management Console, select User Management > User Group to enter the User Management page.
  2. On the User Group Management page, click on the user group to enter the user group details page.
  3. Click on Associated Policies to view the policies already associated.
  4. Click on Associate Policy, select policies from the pop-up policy list.
  5. Click OK to complete the authorization of policies associated with user groups.

Revoking Associated Policies for Sub-users

Directly Revoking Associated Policies for Sub-users

You can directly revoke policies associated with users to revoke the permissions associated with the user.

  1. Log in to the Cloud Access Management Console, select User Management > User to enter the User Management page.
  2. On the User Management page, click on the user to enter the user details page.
  3. Click on Associated Policies to view the policies already associated.
  4. Click Revoke Policy.
  5. Click OK to complete the direct revocation of policies associated with sub-users.

Removing Users from Groups

You can remove users from groups to revoke policies associated with the users.

  1. Log in to the Cloud Access Management Console, select User Management > User Groups to enter the User Group Management page.
  2. On the User Group Management page, click on the user group to enter the user group details page.
  3. Click on Associated Policies to view the policies already associated.
  4. Click Revoke Policy.
  5. Click OK to complete the direct revocation of policies associated with sub-users.