Products Supported by CAM

Last Updated At: 2025-11-26 16:37:57

Introduction

Cloud Access Management already supports permission management for most Cloud Services. This document mainly introduces relevant information about the cloud product services that support Cloud Access Management (CAM). Specific dimensions include authorization granularity, console, authorization based on tags, reference documentation, etc. The following list separately lists the services supported by CAM under various major product categories on the cloud platform. Definitions for the information in the table are as follows:

  • Service: The name of the cloud service that supports CAM, click on the link to the corresponding product service documentation for quick access to relevant information.
  • Authorization Granularity: The minimum authorization granularity provided by the current service.
    Authorization granularity is divided into three levels of granularity: service level, operation level, and resource level.
  • Service Level: Defines whether access permissions to the entire service are granted, divided into allowing full operational permissions for the service or denying all operational permissions for the service.
  • Operation Level: Defines whether access permissions to specific interfaces (APIs) of the service are granted, for example: authorizing an account to perform read-only operations on the Cloud Virtual Machine service.
  • Resource Level: Defines whether access permissions to specific resources are granted. This is the finest authorization granularity, for example: authorizing an account to only read and write operations on a specific Cloud Virtual Machine.
  • Console: Indicates whether sub-accounts can access the current service through the console. "?" indicates support, - indicates temporary lack of support.
  • Authorization Based on Tags: Indicates whether the current service supports permission management based on tags. "?" indicates support, "-" indicates temporary lack of support.
  • Reference Documentation: Link to documents related to CAM for the current service. "-" indicates none available.

Computing

Service Authorization Granularity Console Authorization Based on Tags Service Roles Reference Documentation
Cloud Virtual Machine Resource Level -

|Bare Metal Server|Resource Level|✓|-|-|-|

Storage

Service Authorization Granularity Console Authorization Based on Tags Service Roles Reference Documentation
COS Resource Level -
Cloud File Storage Resource Level -
Cloud Block Storage Resource Level - -

Network

Service Authorization Granularity Console Authorization Based on Tags Service Roles Reference Documentation
Load balancing Resource Level -
Virtual Private Cloud (VPC) Resource Level -

Management and Audit

Service Authorization Granularity Console Authorization Based on Tags Service Roles Reference Documentation
Access Management Operation Level - -
Cloud Audit Operation Level - - -

Monitoring and Operations

Service Authorization Granularity Console Authorization Based on Tags Service Roles Reference Documentation
Cloud Monitor Operation Level - - -

Public Service

Service Authorization Granularity Console Authorization Based on Tags Service Roles Reference Documentation
VPC DNS (VPCDNS) Service Level - - -

Security

Service Authorization Granularity Console Authorization Based on Tags Service Roles Reference Documentation
CWPP (CWP) Service Level - - -
Secrets Manager (SSM) Service Level - - -
Web Application Firewall (WAF) Service Level - - -
Cloud Firewall (CFW) Service Level - - -

Operations Platform

Service Authorization Granularity Console Authorization Based on Tags Service Roles Reference Documentation
Cloud Audit Service Level - - -
Access Management Service Level - - -
Tag Service Level - - -